Vulnerabilities > CVE-2001-1078 - Remote Format String vulnerability in eXtremail
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format specifiers in the SMTP commands (1) HELO, (2) EHLO, (3) MAIL FROM, or (4) RCPT TO, and the POP3 commands (5) USER and (6) other commands that can be executed after POP3 authentication.
Vulnerable Configurations
Exploit-Db
description Linux eXtremail 1.5.x Remote Format Strings Exploit. CVE-2001-1078. Remote exploit for linux platform id EDB-ID:49 last seen 2016-01-31 modified 2003-07-02 published 2003-07-02 reporter B-r00t source https://www.exploit-db.com/download/49/ title Linux eXtremail 1.5.x - Remote Format Strings Exploit description eXtremail 1.x/2.1 Remote Format String Vulnerability (3). CVE-2001-1078. Remote exploit for linux platform id EDB-ID:20954 last seen 2016-02-02 modified 2006-10-06 published 2006-10-06 reporter mu-b source https://www.exploit-db.com/download/20954/ title eXtremail 1.x/2.1 - Remote Format String Vulnerability 3 description eXtremail 1.x/2.1 Remote Format String Vulnerability (2). CVE-2001-1078. Remote exploit for linux platform id EDB-ID:20953 last seen 2016-02-02 modified 2001-06-21 published 2001-06-21 reporter mu-b source https://www.exploit-db.com/download/20953/ title eXtremail 1.x/2.1 - Remote Format String Vulnerability 2 description eXtremail 1.x/2.1 Remote Format String Vulnerability (1). CVE-2001-1078. Dos exploit for linux platform id EDB-ID:20952 last seen 2016-02-02 modified 2001-06-21 published 2001-06-21 reporter Luca Ercoli source https://www.exploit-db.com/download/20952/ title eXtremail 1.x/2.1 - Remote Format String Vulnerability 1
Nessus
NASL family | SMTP problems |
NASL id | EXTREMAIL_FORMAT_STRINGS.NASL |
description | According to its version number, the remote eXtremail server has a format string vulnerability. A remote attacker could exploit this to crash the service, or possibly execute arbitrary code. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11100 |
published | 2002-08-22 |
reporter | This script is Copyright (C) 2002-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11100 |
title | eXtremail Multiple SMTP Command flog Function Format String |