MEDIUM · 6.4

CVE-2001-0996

POP3Lite before 0.2.4 does not properly quote a . (dot) in an email message, which could allow a remote attacker to append arbitrary text to the end of an email message, which could then be interprete...

Vulnerability Description

POP3Lite before 0.2.4 does not properly quote a . (dot) in an email message, which could allow a remote attacker to append arbitrary text to the end of an email message, which could then be interpreted by various mail clients as valid POP server responses or other input that could cause clients to crash or otherwise behave unexpectedly.

CVSS Score

6.4

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:P
Confidentiality
NONE
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Pop3LitePop3Lite0.2.3

References

FAQ

What is CVE-2001-0996?

CVE-2001-0996 is a vulnerability with a CVSS score of 6.4 (MEDIUM). POP3Lite before 0.2.4 does not properly quote a . (dot) in an email message, which could allow a remote attacker to append arbitrary text to the end of an email message, which could then be interprete...

How severe is CVE-2001-0996?

CVE-2001-0996 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2001-0996?

Check the references section above for vendor advisories and patch information. Affected products include: Pop3Lite Pop3Lite.