CVE-2004-2239: Buffer Overflow
Published Dec 31, 2004
·Updated
Buffer overflow in vsybase.c in vpopmail 5.4.2 and earlier might allow attackers to cause a denial of service or execute arbitrary code.
Affected Software
70 affected components
Inter7 Vpopmail \(vchkpw\)=3.4.11e
Inter7 Vpopmail \(vchkpw\)=3.4.1
Inter7 Vpopmail \(vchkpw\)=5.2.1
Inter7 Vpopmail \(vchkpw\)=4.9.10
Inter7 Vpopmail \(vchkpw\)=5.3.30
Inter7 Vpopmail \(vchkpw\)=3.4.6
Inter7 Vpopmail \(vchkpw\)=3.4.11
Inter7 Vpopmail \(vchkpw\)=3.4.2
Inter7 Vpopmail \(vchkpw\)=4.10
Inter7 Vpopmail \(vchkpw\)=3.4.10
Inter7 Vpopmail \(vchkpw\)=4.9
Inter7 Vpopmail \(vchkpw\)=3.4.8
Inter7 Vpopmail \(vchkpw\)=4.6
Inter7 Vpopmail \(vchkpw\)=5.3.28
Inter7 Vpopmail \(vchkpw\)=5.3.27
Inter7 Vpopmail \(vchkpw\)=5.3.22
Inter7 Vpopmail \(vchkpw\)=5.3.21
Inter7 Vpopmail \(vchkpw\)=5.3.26
Inter7 Vpopmail \(vchkpw\)=5.4
Inter7 Vpopmail \(vchkpw\)=3.4.5
Inter7 Vpopmail \(vchkpw\)=4.7
Inter7 Vpopmail \(vchkpw\)=3.4.9
Inter7 Vpopmail \(vchkpw\)=5.3.29
Inter7 Vpopmail \(vchkpw\)=3.4.7
Inter7 Vpopmail \(vchkpw\)=5.4.1
Inter7 Vpopmail \(vchkpw\)=5.3.24
Inter7 Vpopmail \(vchkpw\)=5.3.23
Inter7 Vpopmail \(vchkpw\)=5.3.25
Inter7 Vpopmail \(vchkpw\)=3.4.3
Inter7 Vpopmail \(vchkpw\)=4.8
Inter7 Vpopmail \(vchkpw\)=5.3.20
Inter7 Vpopmail \(vchkpw\)=3.4.4
Inter7 Vpopmail \(vchkpw\)=5.4.2
Inter7 Vpopmail \(vchkpw\)=4.5
Inter7 Vpopmail \(vchkpw\)=5.2.2
Inter7 Vpopmail \(vchkpw\)=3.4.1
Inter7 Vpopmail \(vchkpw\)=3.4.2
Inter7 Vpopmail \(vchkpw\)=3.4.3
Inter7 Vpopmail \(vchkpw\)=3.4.4
Inter7 Vpopmail \(vchkpw\)=3.4.5
Inter7 Vpopmail \(vchkpw\)=3.4.6
Inter7 Vpopmail \(vchkpw\)=3.4.7
Inter7 Vpopmail \(vchkpw\)=3.4.8
Inter7 Vpopmail \(vchkpw\)=3.4.9
Inter7 Vpopmail \(vchkpw\)=3.4.10
Inter7 Vpopmail \(vchkpw\)=3.4.11
Inter7 Vpopmail \(vchkpw\)=3.4.11e
Inter7 Vpopmail \(vchkpw\)=4.5
Inter7 Vpopmail \(vchkpw\)=4.6
Inter7 Vpopmail \(vchkpw\)=4.7
Inter7 Vpopmail \(vchkpw\)=4.8
Inter7 Vpopmail \(vchkpw\)=4.9
Inter7 Vpopmail \(vchkpw\)=4.9.10
Inter7 Vpopmail \(vchkpw\)=4.10
Inter7 Vpopmail \(vchkpw\)=5.2.1
Inter7 Vpopmail \(vchkpw\)=5.2.2
Inter7 Vpopmail \(vchkpw\)=5.3.20
Inter7 Vpopmail \(vchkpw\)=5.3.21
Inter7 Vpopmail \(vchkpw\)=5.3.22
Inter7 Vpopmail \(vchkpw\)=5.3.23
Inter7 Vpopmail \(vchkpw\)=5.3.24
Inter7 Vpopmail \(vchkpw\)=5.3.25
Inter7 Vpopmail \(vchkpw\)=5.3.26
Inter7 Vpopmail \(vchkpw\)=5.3.27
Inter7 Vpopmail \(vchkpw\)=5.3.28
Inter7 Vpopmail \(vchkpw\)=5.3.29
Inter7 Vpopmail \(vchkpw\)=5.3.30
Inter7 Vpopmail \(vchkpw\)=5.4
Inter7 Vpopmail \(vchkpw\)=5.4.1
Inter7 Vpopmail \(vchkpw\)=5.4.2
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Jul 17, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2239?
CVE-2004-2239 is classified as a buffer overflow vulnerability that may allow attackers to execute arbitrary code or induce a denial of service.
2
How do I fix CVE-2004-2239?
To fix CVE-2004-2239, it is recommended to upgrade to a version of vpopmail that is newer than 5.4.2.
3
Which versions are affected by CVE-2004-2239?
CVE-2004-2239 affects vpopmail versions 5.4.2 and earlier.
4
What kind of attack can occur due to CVE-2004-2239?
CVE-2004-2239 can allow attackers to exploit the vulnerability to execute malicious code or disrupt service.
5
Is there a way to mitigate CVE-2004-2239 without upgrading?
While upgrading is the primary solution, implementing network-level protections or access controls may help mitigate the risk of CVE-2004-2239.