CVE-2003-0143: Buffer Overflow
Published Mar 18, 2003
·Updated
The popmsg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authenticated users to execute arbitrary code via a buffer overflow in a mdef command with a long macro name.
Affected Software
4 affected components
Qualcomm Qpopper=4.0.1
Qualcomm Qpopper=4.0.4
Qualcomm Qpopper=4.0.3
Qualcomm Qpopper=4.0.2
Remediation
Patch Available
Patch Available
Event History
Mar 18, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-0143?
CVE-2003-0143 has a high severity due to the potential for authenticated users to execute arbitrary code via a buffer overflow.
2
How do I fix CVE-2003-0143?
To fix CVE-2003-0143, upgrade qpopper to version 4.0.5fc2 or later.
3
Which versions of qpopper are affected by CVE-2003-0143?
CVE-2003-0143 affects qpopper versions 4.0.1 through 4.0.4.
4
What type of vulnerability is CVE-2003-0143?
CVE-2003-0143 is a buffer overflow vulnerability.
5
Can CVE-2003-0143 be exploited remotely?
CVE-2003-0143 cannot be exploited remotely as it requires authenticated users to trigger the vulnerability.