vendor:
Squirrelmail
by:
Bytes <Bytes[at]ph4nt0m.net>
9
CVSS
CRITICAL
Local Root Exploit
119
CWE
Product Name: Squirrelmail
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2004
Squirrelmail chpasswd Local Root Bruteforce Exploit
This exploit is a local root bruteforce exploit for Squirrelmail chpasswd. It allows an attacker to gain root privileges on a system by exploiting a vulnerability in the chpasswd program. The exploit uses a buffer overflow to overwrite the return address on the stack and execute arbitrary code with root privileges. The exploit requires the attacker to have access to an account belonging to the webmaster, www, or other webserver groups.
Mitigation:
The vulnerability can be mitigated by patching the chpasswd program to prevent buffer overflows. It is also recommended to restrict access to accounts belonging to the webmaster, www, or other webserver groups.