Vulnerability Description
Qpopper 2.53 and earlier allows local users to gain privileges via a formatting string in the From: header, which is processed by the euidl command.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Qpopper | 2.52 |
| Sun | Cobalt Raq 2 | All versions |
| Sun | Cobalt Raq 3I | All versions |
References
- http://archives.neohapsis.com/archives/bugtraq/2000-05/0267.html
- http://www.novell.com/linux/security/advisories/suse_security_announce_51.html
- http://www.securityfocus.com/bid/1242
- http://archives.neohapsis.com/archives/bugtraq/2000-05/0267.html
- http://www.novell.com/linux/security/advisories/suse_security_announce_51.html
- http://www.securityfocus.com/bid/1242
FAQ
What is CVE-2000-0442?
CVE-2000-0442 is a vulnerability with a CVSS score of 7.5 (HIGH). Qpopper 2.53 and earlier allows local users to gain privileges via a formatting string in the From: header, which is processed by the euidl command.
How severe is CVE-2000-0442?
CVE-2000-0442 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2000-0442?
Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Qpopper, Sun Cobalt Raq 2, Sun Cobalt Raq 3I.