Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Qualcomm Qpopper Username Remote Overflow

Critical

Synopsis

The remote host is vulnerable to a buffer overflow.

Description

In version 4, a buffer overflow was introduced into the qpopper source tree. This buffer overflow is related to the handling of the client-supplied username and is present when a POP3 session is being initiated. It is believed that the overflow occurs before authentication, so it may not be required that users have valid POP accounts. This vulnerability can lead to a compromise of root privileges to remote attackers.

Solution

Upgrade to the latest version.