CVE-2000-0442: High severity Qualcomm Qpopper vulnerability
Qpopper 2.53 and earlier allows local users to gain privileges via a formatting string in the From: header, which is processed by the euidl command.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Sun Cobalt RaQfrom your environment.Disable or uninstall Qpopper from Sun Cobalt RaQ systems or otherwise remove the vulnerable mail-processing component until a vendor-provided fix is available.
- Compensating control
Restrict local user access to systems running Qpopper and avoid running the mail-processing euidl functionality with elevated privileges until the issue is remediated.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0442?
CVE-2000-0442 is classified as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2000-0442?
To fix CVE-2000-0442, it is recommended to upgrade to a version of Qpopper later than 2.53.
What software is affected by CVE-2000-0442?
CVE-2000-0442 affects Qpopper versions 2.52 and earlier, as well as specific Sun Cobalt RaQ systems.
Can CVE-2000-0442 be exploited remotely?
CVE-2000-0442 primarily affects local users who have access to the vulnerable Qpopper installations.
What impact does CVE-2000-0442 have on systems?
CVE-2000-0442 allows local users to execute arbitrary code with elevated privileges, which can compromise system integrity.