PT-2006-1403 · Squirrelmail · Squirrelmail
Rod Hedor
·
Published
2006-01-21
·
Updated
2018-10-19
·
CVE-2006-0331
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SquirrelMail plugin chpasswd version 3.1
Description
A buffer overflow issue in the Change passwd 3.1 (chpasswd) SquirrelMail plugin allows local users to execute arbitrary code via long command line arguments.
Recommendations
For SquirrelMail plugin chpasswd version 3.1, update to a version that fixes this issue to prevent arbitrary code execution.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Squirrelmail