Inter7 vpopmail (vchkpw) Buffer Overflow Vulnerability
BID:942
Info
Inter7 vpopmail (vchkpw) Buffer Overflow Vulnerability
| Bugtraq ID: | 942 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jan 21 2000 12:00AM |
| Updated: | Jan 21 2000 12:00AM |
| Credit: | This vulnerability was detailed in a W00W00 advisory by K2 <[email protected]>. This advisory was posted to the Bugtraq mailing list on Sat, 22 Jan 2000 by K2 <[email protected]>. |
| Vulnerable: |
Inter7 vpopmail (vchkpw) 3.4.11 Inter7 vpopmail (vchkpw) 3.4.10 Inter7 vpopmail (vchkpw) 3.4.9 Inter7 vpopmail (vchkpw) 3.4.8 Inter7 vpopmail (vchkpw) 3.4.7 Inter7 vpopmail (vchkpw) 3.4.6 Inter7 vpopmail (vchkpw) 3.4.5 Inter7 vpopmail (vchkpw) 3.4.4 Inter7 vpopmail (vchkpw) 3.4.3 Inter7 vpopmail (vchkpw) 3.4.2 Inter7 vpopmail (vchkpw) 3.4.1 |
| Not Vulnerable: |
Inter7 vpopmail (vchkpw) 3.4.11 e |
Discussion
Inter7 vpopmail (vchkpw) Buffer Overflow Vulnerability
Vpopmail (vchkpw) is free GPL software package built to help manage virtual domains and non /etc/passwd email accounts on Qmail mail servers. This package is developed by Inter7 (Referenced in the 'Credit' section) and is not shipped, maintained or supported by the main Qmail distribution.
Certain versions of this software are vulnerable to a remote buffer overflow attack in the password authentication of vpopmail.
Vpopmail (vchkpw) is free GPL software package built to help manage virtual domains and non /etc/passwd email accounts on Qmail mail servers. This package is developed by Inter7 (Referenced in the 'Credit' section) and is not shipped, maintained or supported by the main Qmail distribution.
Certain versions of this software are vulnerable to a remote buffer overflow attack in the password authentication of vpopmail.