多厂商popd锁定文件拒绝服务漏洞

多厂商popd锁定文件拒绝服务漏洞

漏洞ID 1105808 漏洞类型 访问验证错误
发布时间 2000-04-19 更新时间 2005-10-20
图片[1]-多厂商popd锁定文件拒绝服务漏洞-安全小百科CVE编号 CVE-2000-1198
图片[2]-多厂商popd锁定文件拒绝服务漏洞-安全小百科CNNVD-ID CNNVD-200108-166
漏洞平台 Linux CVSS评分 2.1
|漏洞来源
https://www.exploit-db.com/exploits/19869
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200108-166
|漏洞详情
qpopperPOP服务器会创建带有可预测名称的锁定文件,本地用户可以通过创建其他邮箱的锁定文件导致这些用户的服务拒绝(无法访问邮件)。
|漏洞EXP
source: http://www.securityfocus.com/bid/1132/info

Vulnerabilities exist in a number of pop3 daemon implementations, having to do with their creation of lock files. Affected include Qualcomm's qpopper, and the popd included as part of the imap-4 rpm from RedHat. Lockfiles in both implementation are created with consistent local file names; the RedHat popd in /tmp, with a fairly random name (albeit consistent for a given user), and in the mail spool directory, with the user name prepended by a "." and appended with ".pop". Creation of either of these files will prevent the popd user from being able to establish a connection to retrieve their mail.

The FreeBSD port of imap-uw contains this vulnerability. It is not, however, included as a standard part of a FreeBSD install.

touch /var/mail/.username.pop
|参考资料

来源:BID
名称:1132
链接:http://www.securityfocus.com/bid/1132
来源:BUGTRAQ
名称:20000420pop3
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=95634229925906&w;=2
来源:BUGTRAQ
名称:20000420pop3d/imapDOS(whilewe’reonthesubject)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=95624629924545&w;=2

相关推荐: Microsoft SQL Server 2000 Incorrect Registry Key Permissions Vulnerability

Microsoft SQL Server 2000 Incorrect Registry Key Permissions Vulnerability 漏洞ID 1102246 漏洞类型 Access Validation Error 发布时间 2002-04-…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享