Vulnerabilities > CVE-2004-0524 - Buffer Overrun vulnerability in SquirrelMail Change_Passwd Plug-in

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
thiago-melo-de-paula
critical
exploit available

Summary

Buffer overflow in the chpasswd command in the Change_passwd plugin before 4.0, as used in SquirrelMail, allows local users to gain root privileges via a long user name.

Vulnerable Configurations

Part Description Count
Application
Thiago_Melo_De_Paula
1

Exploit-Db

  • descriptionSquirrelMail chpasswd buffer overflow. CVE-2004-0524. Local exploit for linux platform
    idEDB-ID:273
    last seen2016-01-31
    modified2004-04-20
    published2004-04-20
    reporterx314
    sourcehttps://www.exploit-db.com/download/273/
    titleSquirrelMail chpasswd Buffer Overflow
  • descriptionSquirrelMail (chpasswd) Local Root Bruteforce Exploit. CVE-2004-0524. Local exploit for linux platform
    idEDB-ID:417
    last seen2016-01-31
    modified2004-08-25
    published2004-08-25
    reporterBytes
    sourcehttps://www.exploit-db.com/download/417/
    titleSquirrelMail chpasswd Local Root Bruteforce Exploit