First published: Fri Aug 31 2001(Updated: )
POP2 or POP3 server (pop3d) in imap-uw IMAP package on FreeBSD and other operating systems creates lock files with predictable names, which allows local users to cause a denial of service (lack of mail access) for other users by creating lock files for other mail boxes.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
University of Washington c-client | =4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-1197 is considered a denial-of-service vulnerability that can affect mail access for users.
To fix CVE-2000-1197, ensure that your POP2 and POP3 servers do not create predictable lock file names and update the imap-uw IMAP package to a secure version.
CVE-2000-1197 affects the imap-uw IMAP package on FreeBSD and potentially other operating systems.
CVE-2000-1197 is a local denial-of-service vulnerability, meaning that it cannot be exploited remotely.
Local users on systems running the imap-uw IMAP package with version 4.5 are vulnerable to CVE-2000-1197.