Vulnerability CVE-2001-1078


Published: 2001-06-21   Modified: 2012-02-12

Description:
Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format specifiers in the SMTP commands (1) HELO, (2) EHLO, (3) MAIL FROM, or (4) RCPT TO, and the POP3 commands (5) USER and (6) other commands that can be executed after POP3 authentication.

Type:

CWE-Other

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Extremail -> Extremail 

 References:
http://archives.neohapsis.com/archives/bugtraq/2001-06/0291.html
http://www.extremail.com/history.htm
http://www.extremail.com/news.htm
http://www.securityfocus.com/bid/2908
https://exchange.xforce.ibmcloud.com/vulnerabilities/6733

Copyright 2024, cxsecurity.com

 

Back to Top