First published: Fri Dec 31 2004(Updated: )
** DISPUTED ** Format string vulnerability in vsybase.c in vpopmail 5.4.2 and earlier has unknown impact and attack vectors. NOTE: in a followup post, it was observed that the source code used constants that, when compiled, became static format strings. Thus this is not a vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Inter7 Vpopmail Vchkpw | =3.4.11e | |
Inter7 Vpopmail Vchkpw | =3.4.1 | |
Inter7 Vpopmail Vchkpw | =5.2.1 | |
Inter7 Vpopmail Vchkpw | =4.9.10 | |
Inter7 Vpopmail Vchkpw | =5.3.30 | |
Inter7 Vpopmail Vchkpw | =3.4.6 | |
Inter7 Vpopmail Vchkpw | =3.4.11 | |
Inter7 Vpopmail Vchkpw | =3.4.2 | |
Inter7 Vpopmail Vchkpw | =4.10 | |
Inter7 Vpopmail Vchkpw | =3.4.10 | |
Inter7 Vpopmail Vchkpw | =4.9 | |
Inter7 Vpopmail Vchkpw | =3.4.8 | |
Inter7 Vpopmail Vchkpw | =4.6 | |
Inter7 Vpopmail Vchkpw | =5.3.28 | |
Inter7 Vpopmail Vchkpw | =5.3.27 | |
Inter7 Vpopmail Vchkpw | =5.3.22 | |
Inter7 Vpopmail Vchkpw | =5.3.21 | |
Inter7 Vpopmail Vchkpw | =5.3.26 | |
Inter7 Vpopmail Vchkpw | =5.4 | |
Inter7 Vpopmail Vchkpw | =3.4.5 | |
Inter7 Vpopmail Vchkpw | =4.7 | |
Inter7 Vpopmail Vchkpw | =3.4.9 | |
Inter7 Vpopmail Vchkpw | =5.3.29 | |
Inter7 Vpopmail Vchkpw | =3.4.7 | |
Inter7 Vpopmail Vchkpw | =5.4.1 | |
Inter7 Vpopmail Vchkpw | =5.3.24 | |
Inter7 Vpopmail Vchkpw | =5.3.23 | |
Inter7 Vpopmail Vchkpw | =5.3.25 | |
Inter7 Vpopmail Vchkpw | =3.4.3 | |
Inter7 Vpopmail Vchkpw | =4.8 | |
Inter7 Vpopmail Vchkpw | =5.3.20 | |
Inter7 Vpopmail Vchkpw | =3.4.4 | |
Inter7 Vpopmail Vchkpw | =5.4.2 | |
Inter7 Vpopmail Vchkpw | =4.5 | |
Inter7 Vpopmail Vchkpw | =5.2.2 | |
Inter7 Vpopmail Vchkpw | =3.4.1 | |
Inter7 Vpopmail Vchkpw | =3.4.2 | |
Inter7 Vpopmail Vchkpw | =3.4.3 | |
Inter7 Vpopmail Vchkpw | =3.4.4 | |
Inter7 Vpopmail Vchkpw | =3.4.5 | |
Inter7 Vpopmail Vchkpw | =3.4.6 | |
Inter7 Vpopmail Vchkpw | =3.4.7 | |
Inter7 Vpopmail Vchkpw | =3.4.8 | |
Inter7 Vpopmail Vchkpw | =3.4.9 | |
Inter7 Vpopmail Vchkpw | =3.4.10 | |
Inter7 Vpopmail Vchkpw | =3.4.11 | |
Inter7 Vpopmail Vchkpw | =3.4.11e | |
Inter7 Vpopmail Vchkpw | =4.5 | |
Inter7 Vpopmail Vchkpw | =4.6 | |
Inter7 Vpopmail Vchkpw | =4.7 | |
Inter7 Vpopmail Vchkpw | =4.8 | |
Inter7 Vpopmail Vchkpw | =4.9 | |
Inter7 Vpopmail Vchkpw | =4.9.10 | |
Inter7 Vpopmail Vchkpw | =4.10 | |
Inter7 Vpopmail Vchkpw | =5.2.1 | |
Inter7 Vpopmail Vchkpw | =5.2.2 | |
Inter7 Vpopmail Vchkpw | =5.3.20 | |
Inter7 Vpopmail Vchkpw | =5.3.21 | |
Inter7 Vpopmail Vchkpw | =5.3.22 | |
Inter7 Vpopmail Vchkpw | =5.3.23 | |
Inter7 Vpopmail Vchkpw | =5.3.24 | |
Inter7 Vpopmail Vchkpw | =5.3.25 | |
Inter7 Vpopmail Vchkpw | =5.3.26 | |
Inter7 Vpopmail Vchkpw | =5.3.27 | |
Inter7 Vpopmail Vchkpw | =5.3.28 | |
Inter7 Vpopmail Vchkpw | =5.3.29 | |
Inter7 Vpopmail Vchkpw | =5.3.30 | |
Inter7 Vpopmail Vchkpw | =5.4 | |
Inter7 Vpopmail Vchkpw | =5.4.1 | |
Inter7 Vpopmail Vchkpw | =5.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2004-2238 is currently disputed and considered low due to the nature of the vulnerability.
Vpopmail versions 5.4.2 and earlier are affected by CVE-2004-2238.
Currently, there is no necessary fix for CVE-2004-2238 as the vulnerability has been disputed, indicating it may not exist.
CVE-2004-2238 is disputed and may not be a confirmed vulnerability in Vpopmail.
A format string vulnerability like CVE-2004-2238 involves improper handling of format strings in programming, but its impact is unclear in this case.