Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

POP3:OVERFLOW:QPOP-OF2

Severity

Critical

Recommended

No

Recommended Action

Drop

Category

POP3

Release Date

2003/04/22

Update Number

1213

Supported Platforms

di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

POP3: Qpopper LIST Overflow


This signature detects an attempt to exploit a vulnerability in Qpopper. Version 3.0beta30 and many earlier versions are vulnerable. Authenticated users can exploit this vulnerability to execute commands on the server, or to access mailboxes of other users.

Extended Description

A remotely exploitable buffer-overflow vulnerability affects Qualcomm's 'qpopper' daemon. This issue allows users already in possession of a username and password for a POP account to compromise the server running the qpopper daemon. The problem lies in the code that handles the 'LIST' command available to logged-in users. By providing an overly long argument, an attacker may cause a buffer to overflow. As a result, the attacker can gain access with the user ID (UID) of the user whose account is being used for the attack and with the group ID (GID) mail. This will allow remote attackers to access the server itself and possibly (depending on how the computer is configured) to read other users' mail via the GID mail.

Affected Products

  • Qualcomm qpopper 3.0.0
  • Qualcomm qpopper 3.0.0 beta1
  • Qualcomm qpopper 3.0.0 beta10
  • Qualcomm qpopper 3.0.0 beta11
  • Qualcomm qpopper 3.0.0 beta12
  • Qualcomm qpopper 3.0.0 beta13
  • Qualcomm qpopper 3.0.0 beta14
  • Qualcomm qpopper 3.0.0 beta15
  • Qualcomm qpopper 3.0.0 beta16
  • Qualcomm qpopper 3.0.0 beta17
  • Qualcomm qpopper 3.0.0 beta18
  • Qualcomm qpopper 3.0.0 beta19
  • Qualcomm qpopper 3.0.0 beta2
  • Qualcomm qpopper 3.0.0 beta20
  • Qualcomm qpopper 3.0.0 beta21
  • Qualcomm qpopper 3.0.0 beta22
  • Qualcomm qpopper 3.0.0 beta23
  • Qualcomm qpopper 3.0.0 beta24
  • Qualcomm qpopper 3.0.0 beta25
  • Qualcomm qpopper 3.0.0 beta26
  • Qualcomm qpopper 3.0.0 beta27
  • Qualcomm qpopper 3.0.0 beta28
  • Qualcomm qpopper 3.0.0 beta29
  • Qualcomm qpopper 3.0.0 beta3
  • Qualcomm qpopper 3.0.0 beta4
  • Qualcomm qpopper 3.0.0 beta5
  • Qualcomm qpopper 3.0.0 beta6
  • Qualcomm qpopper 3.0.0 beta7
  • Qualcomm qpopper 3.0.0 beta8
  • Qualcomm qpopper 3.0.0 beta9

References

  • BugTraq: 948
  • CVE: CVE-2000-0096
  • URL: http://www.securityspace.com/smysecure/catid.html?viewsrc=1&id=10197
  • URL: http://www3.ca.com/securityadvisor/vulninfo/Vuln.aspx?ID=2333

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out