PT-2006-2168 · Qmail · Qmailadmin

Publicado

2006-03-10

·

Atualizado

2017-07-20

·

CVE-2006-1141

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions QmailAdmin versions prior to 1.2.10
Description The issue is related to a buffer overflow in the qmailadmin.c file. This can be exploited by remote attackers who send a long PATH INFO environment variable, allowing them to execute arbitrary code.
Recommendations For versions prior to 1.2.10, update to version 1.2.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the qmailadmin.c file to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-1141

Produtos afetados

Qmailadmin