CVE-2005-1151: High severity Debian Qpopper vulnerability
Published May 25, 2005
·Updated
qpopper 4.0.5 and earlier does not properly drop privileges before processing certain user-supplied files, which allows local users to overwrite or create arbitrary files as root.
Affected Software
2 affected components
Debian Qpopper<=4.0.4
Debian Qpopper=4.0.5
Remediation
Patch Available
Event History
May 25, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1151?
CVE-2005-1151 is considered a high severity vulnerability due to the potential for local users to gain unauthorized root access.
2
How do I fix CVE-2005-1151?
To fix CVE-2005-1151, upgrade qpopper to version 4.0.6 or later to ensure proper privilege management.
3
Who is affected by CVE-2005-1151?
CVE-2005-1151 affects versions of qpopper up to and including 4.0.5 on Debian-based systems.
4
What kind of attack does CVE-2005-1151 allow?
CVE-2005-1151 allows local users to overwrite or create arbitrary files with root permissions.
5
Is there a workaround for CVE-2005-1151?
A temporary workaround for CVE-2005-1151 is to restrict local user access to the affected system until an upgrade can be applied.