Qualcomm qpopper 'LIST' Buffer Overflow Vulnerability
BID:948
Info
Qualcomm qpopper 'LIST' Buffer Overflow Vulnerability
| Bugtraq ID: | 948 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2000-0096 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jan 26 2000 12:00AM |
| Updated: | Sep 28 2006 06:25PM |
| Credit: | This bug was discovered by the !Hispahack Research Team and was posted to the Bugtraq mailing list by Zhodiac <[email protected]> on Wed, 26 Jan 2000. |
| Vulnerable: |
Qualcomm qpopper 3.0 beta9 Qualcomm qpopper 3.0 beta8 Qualcomm qpopper 3.0 beta7 Qualcomm qpopper 3.0 beta6 Qualcomm qpopper 3.0 beta5 Qualcomm qpopper 3.0 beta4 Qualcomm qpopper 3.0 beta3 Qualcomm qpopper 3.0 beta29 Qualcomm qpopper 3.0 beta28 Qualcomm qpopper 3.0 beta27 Qualcomm qpopper 3.0 beta26 Qualcomm qpopper 3.0 beta25 Qualcomm qpopper 3.0 beta24 Qualcomm qpopper 3.0 beta23 Qualcomm qpopper 3.0 beta22 Qualcomm qpopper 3.0 beta21 Qualcomm qpopper 3.0 beta20 Qualcomm qpopper 3.0 beta2 Qualcomm qpopper 3.0 beta19 Qualcomm qpopper 3.0 beta18 Qualcomm qpopper 3.0 beta17 Qualcomm qpopper 3.0 beta16 Qualcomm qpopper 3.0 beta15 Qualcomm qpopper 3.0 beta14 Qualcomm qpopper 3.0 beta13 Qualcomm qpopper 3.0 beta12 Qualcomm qpopper 3.0 beta11 Qualcomm qpopper 3.0 beta10 Qualcomm qpopper 3.0 beta1 Qualcomm qpopper 3.0 |
| Not Vulnerable: |
Qualcomm qpopper 4.0.8 Qualcomm qpopper 4.0.7 Qualcomm qpopper 4.0.6 Qualcomm qpopper 4.0.5 fc2 Qualcomm qpopper 4.0.5 Qualcomm qpopper 4.0.4 Qualcomm qpopper 4.0.3 Qualcomm qpopper 4.0.2 Qualcomm qpopper 4.0.1 Qualcomm qpopper 4.0 b14 Qualcomm qpopper 4.0 3 Qualcomm qpopper 4.0 2 Qualcomm qpopper 4.0 1 Qualcomm qpopper 4.0 Qualcomm qpopper 3.0 beta31 Qualcomm qpopper 3.0 beta30 Qualcomm qpopper 2.53 Qualcomm qpopper 2.52 Qualcomm qpopper 2.4 Qualcomm qpopper 4.0 |
Discussion
Qualcomm qpopper 'LIST' Buffer Overflow Vulnerability
A remotely exploitable buffer-overflow vulnerability affects Qualcomm's 'qpopper' daemon. This issue allows users already in possession of a username and password for a POP account to compromise the server running the qpopper daemon.
The problem lies in the code that handles the 'LIST' command available to logged-in users. By providing an overly long argument, an attacker may cause a buffer to overflow. As a result, the attacker can gain access with the user ID (UID) of the user whose account is being used for the attack and with the group ID (GID) mail.
This will allow remote attackers to access the server itself and possibly (depending on how the computer is configured) to read other users' mail via the GID mail.
A remotely exploitable buffer-overflow vulnerability affects Qualcomm's 'qpopper' daemon. This issue allows users already in possession of a username and password for a POP account to compromise the server running the qpopper daemon.
The problem lies in the code that handles the 'LIST' command available to logged-in users. By providing an overly long argument, an attacker may cause a buffer to overflow. As a result, the attacker can gain access with the user ID (UID) of the user whose account is being used for the attack and with the group ID (GID) mail.
This will allow remote attackers to access the server itself and possibly (depending on how the computer is configured) to read other users' mail via the GID mail.
Exploit / POC
Qualcomm qpopper 'LIST' Buffer Overflow Vulnerability
An exploit is available:
An exploit is available:
Solution / Fix
Qualcomm qpopper 'LIST' Buffer Overflow Vulnerability
Solution:
The vendor released fixes to address this issue. Please see the references section for further information.
Solution:
The vendor released fixes to address this issue. Please see the references section for further information.
References
Qualcomm qpopper 'LIST' Buffer Overflow Vulnerability
References:
References:
- !Hispahack Research Team Home Page (!Hispahack Research Team)
- Qpopper Homepage (Qualcomm)
- Qpopper Security Vulnerability (Qualcomm)