CVE-1999-0822: Buffer Overflow
Buffer overflow in Qpopper (qpop) 3.0 allows remote root access via AUTH command.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Qpopper (qpop)from your environment.Uninstall Qpopper from affected systems if the POP3 service is not required.
- Configuration
Disable support for the POP AUTH command in Qpopper to mitigate the buffer overflow via AUTH.
Qpopper (qpop) AUTH command = disabled - Compensating control
Restrict access to the POP3 service to trusted hosts or networks using firewall rules or ACLs to reduce exposure to the vulnerable AUTH command.
- Operational
If systems may have been exposed, perform incident response actions: audit for signs of root compromise, reinstall or restore affected systems from trusted media, and rotate root and any other potentially exposed credentials.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0822?
CVE-1999-0822 is considered to have a high severity due to its potential for remote root access.
How do I fix CVE-1999-0822?
To fix CVE-1999-0822, upgrade Qpopper to version 3.0b21 or later.
What is the impact of CVE-1999-0822?
The impact of CVE-1999-0822 is that an attacker can execute arbitrary code with root privileges.
Which versions of Qpopper are affected by CVE-1999-0822?
Qpopper versions 3.0 and 3.0b20 are affected by CVE-1999-0822.
Is CVE-1999-0822 specific to any operating systems?
CVE-1999-0822 affects any operating system running the vulnerable versions of Qpopper.