PT-2000-1526 · Winproxy · Winproxy
Published
2000-06-27
·
Updated
2008-09-10
·
CVE-2000-0592
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
WinProxy versions 2.0 through 2.0.1
Description
The issue concerns buffer overflows in the POP3 service, allowing remote attackers to execute arbitrary commands. This can be achieved by sending long commands such as
USER, PASS, LIST, RETR, or DELE.Recommendations
For WinProxy version 2.0, update to a version that fixes the buffer overflow issue in the POP3 service.
For WinProxy version 2.0.1, update to a version that fixes the buffer overflow issue in the POP3 service.
As a temporary workaround, consider restricting access to the POP3 service until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Winproxy