vendor:
imap
by:
mandark
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: imap
Affected Version From: 4.55
Affected Version To: 4.7c
Patch Exists: YES
Related CWE: N/A
CPE: a:uw:imap
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Unix and Unix-like operating systems
2000
ipop2d Vulnerability
ipop2d is part of the University of Washington imap package. Versions through 4.7c of the imap package are affected. Any user who has a pop account on the machine can view any world or group readable file on the file system. While on a shell account this is not a vulnerability, on a machine where a user only has POP access, this could result in the disclosure of information that might be useful in gaining information about other users on the system. This could in turn potentially be used to gain further access to the machine.
Mitigation:
Ensure that all users have secure passwords and that all accounts are properly secured.