First published: Mon Aug 12 2002(Updated: )
Qpopper (aka in.qpopper or popper) 4.0.3 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a very large string, which causes an infinite loop.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm Qpopper | =4.0.1 | |
Qualcomm Qpopper | =4.0.3 | |
Qualcomm Qpopper | =4.0 | |
Qualcomm Qpopper | =4.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0454 has a moderate severity level due to its potential for causing denial of service through CPU consumption.
To fix CVE-2002-0454, upgrade Qpopper to version 4.0.4 or later, which addresses the vulnerability.
Versions 4.0.1, 4.0.2, 4.0.3, and 4.0 of Qpopper are affected by CVE-2002-0454.
CVE-2002-0454 is exploited through a denial of service attack that causes an infinite loop when processing a very large string.
The vendor for the affected software is Qualcomm, which developed the Qpopper application.