First published: Fri Aug 31 2001(Updated: )
qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm Qpopper | =2.53 | |
Qualcomm Qpopper | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-1198 allows local users to disrupt email access for others by creating lock files with predictable names.
CVE-2000-1198 affects Qualcomm Qpopper versions 2.53 and 3.0.
To mitigate CVE-2000-1198, restrict file system permissions on lock files or upgrade to a version of Qpopper that addresses this vulnerability.
CVE-2000-1198 is classified as a denial of service vulnerability.
CVE-2000-1198 is a local vulnerability, requiring local user access to exploit.