Description
vchkpw program in vpopmail before version 4.8 does not properly cleanse an untrusted format string used in a call to syslog, which allows remote attackers to cause a denial of service via a USER or PASS command that contains arbitrary formatting directives.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2000-0579 | vchkpw program in vpopmail before version 4.8 does not properly cleanse an untrusted format string used in a call to syslog, which allows remote attackers to cause a denial of service via a USER or PASS command that contains arbitrary formatting directives. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T05:21:31.264Z
Reserved: 2000-07-19T00:00:00.000Z
Link: CVE-2000-0583
No data.
Status : Modified
Published: 2000-06-30T04:00:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2000-0583
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD