CVE-1999-0006: Buffer Overflow
Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Qpopperfrom your environment.Uninstall or disable Qpopper and stop the POP service on affected systems until an official fix or patch is available.
- Compensating control
Restrict network access to the POP service (Qpopper) until a fix is available. Use firewall rules/ACLs to block or limit external access to the POP server to only trusted administrative hosts or internal networks.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0006?
CVE-1999-0006 is considered critical due to its potential to allow remote attackers to gain root access.
How do I fix CVE-1999-0006?
To fix CVE-1999-0006, it is recommended to upgrade to a later version of Qpopper that addresses this vulnerability.
Who is affected by CVE-1999-0006?
CVE-1999-0006 affects systems running Qualcomm's Qpopper version 2.4, which uses BSD-based POP server implementations.
What causes CVE-1999-0006?
CVE-1999-0006 is caused by a buffer overflow vulnerability triggered by a long PASS command sent to the POP server.
Can CVE-1999-0006 be exploited remotely?
Yes, CVE-1999-0006 can be exploited remotely, allowing attackers to execute arbitrary code with root privileges.