vendor:
qpopper
by:
WaR and zav
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: qpopper
Affected Version From: 2.4
Affected Version To: 2.5
Patch Exists: YES
Related CWE: N/A
CPE: a:qualcomm:qpopper
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2001
Buffer Overflow in Qualcomm qpopper
A number of buffer-overflow issues reside in versions prior to 2.5 of Qualcomm's 'qpopper' program. Exploiting this issue allows a remote attacker to execute arbitrary commands on hosts that are running a vulnerable version. To determine if you are vulnerable, telnet to port 110 on the possibly vulnerable host. A banner appears, informing you of the version of the pop server. If any version prior to 2.5 is reported, including 2.5 beta, you should upgrade immediately to the latest version.
Mitigation:
Upgrade to the latest version of qpopper