CVE-2000-0091: Buffer Overflow
Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long username or password.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Inter7 Vpopmailfrom your environment.Uninstall Inter7 Vpopmail if the component is not required, to eliminate the vulnerable POP authentication package.
- Configuration
Disable or stop the vchkpw/vpopmail POP authentication service until a vendor fix is available.
Inter7 Vpopmail (vchkpw POP authentication) enabled = false - Compensating control
Restrict network access to the vpopmail/POP authentication service at the perimeter (firewall/ACLs) or otherwise block access to the service until a fix is provided.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0091?
The severity of CVE-2000-0091 is considered high due to the potential for remote attackers to gain root privileges.
How do I fix CVE-2000-0091?
To fix CVE-2000-0091, upgrade to a patched version of vpopmail that addresses the buffer overflow vulnerability.
Which versions of vpopmail are affected by CVE-2000-0091?
CVE-2000-0091 affects multiple versions of vpopmail including 3.4.1, 3.4.2, 3.4.3, 3.4.4, 3.4.5, 3.4.6, 3.4.7, 3.4.8, 3.4.9, and 3.4.11.
What type of vulnerability is CVE-2000-0091?
CVE-2000-0091 is a buffer overflow vulnerability that allows remote code execution.
Who can exploit CVE-2000-0091?
CVE-2000-0091 can be exploited by any remote attacker who can supply a long username or password during the POP authentication process.