PT-2002-2274 · Trend Micro · Pc-Cillin

Published

2002-12-18

·

Updated

2024-02-14

·

CVE-2002-1349

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: PC-cillin versions 2000, 2002, 2003
Description: The issue allows local users to execute arbitrary code via a long input string to the TCP port 110, which is used for POP3. This is due to a buffer overflow in the pop3trap.exe component.
Recommendations: For PC-cillin versions 2000, 2002, 2003, consider restricting access to TCP port 110 until a fix is available. As a temporary workaround, consider disabling the pop3trap.exe component to prevent exploitation.

Exploit

Fix

Related Identifiers

CVE-2002-1349

Affected Products

Pc-Cillin