vendor:
qpopper
by:
Miroslaw Grzybek
7.5
CVSS
HIGH
Buffer Overflow
120 (Buffer Copy without Checking Size of Input)
CWE
Product Name: qpopper
Affected Version From: 2.1.4-R3
Affected Version To: 2.5
Patch Exists: YES
Related CWE: N/A
CPE: //a:qualcomm:qpopper
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: FreeBSD 3.0, FreeBSD 2.2.x, BSDI BSD/OS 2.1
1999
Qualcomm qpopper Buffer Overflow Vulnerability
A number of buffer-overflow issues reside in versions prior to 2.5 of Qualcomm's 'qpopper' program. Exploiting this issue allows a remote attacker to execute arbitrary commands on hosts that are running a vulnerable version. To determine if you are vulnerable, telnet to port 110 on the possibly vulnerable host. If any version prior to 2.5 is reported, including 2.5 beta, you should upgrade immediately to the latest version.
Mitigation:
Upgrade to the latest version of qpopper