Vulnerability Description
Buffer overflow in qwik-smtpd allows remote attackers to use the server as an SMTP spam relay via a long HELO command, which overwrites the adjacent localIP data buffer.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amir Malik | Qwik Smtpd | All versions |
References
- http://tigger.uic.edu/~jlongs2/holes/qwik-smtpd.txtExploitVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18555
- http://tigger.uic.edu/~jlongs2/holes/qwik-smtpd.txtExploitVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18555
FAQ
What is CVE-2004-1291?
CVE-2004-1291 is a vulnerability with a CVSS score of 7.5 (HIGH). Buffer overflow in qwik-smtpd allows remote attackers to use the server as an SMTP spam relay via a long HELO command, which overwrites the adjacent localIP data buffer.
How severe is CVE-2004-1291?
CVE-2004-1291 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-1291?
Check the references section above for vendor advisories and patch information. Affected products include: Amir Malik Qwik Smtpd.