Vulnerability Name: | CVE-1999-1224 (CCN-349) | ||||||||
Assigned: | 1997-10-01 | ||||||||
Published: | 1997-10-01 | ||||||||
Updated: | 2017-12-19 | ||||||||
Summary: | IMAP 4.1 BETA, and possibly other versions, does not properly handle the SIGABRT (abort) signal, which allows local users to crash the server (imapd) via certain sequences of commands, which causes a core dump that may contain sensitive password information. | ||||||||
CVSS v3 Severity: | 5.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 3.6 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-1999-1224 Source: BUGTRAQ Type: UNKNOWN 19971008 L0pht Advisory: IMAP4rev1 imapd server Source: CCN Type: @stake, Inc./L0pht Security Advisory 10/08/97 imapd (imap-4.1BETA from the IMAP 4.1 toolkit from University of Washington) Source: CCN Type: OSVDB ID: 519 UoW imapd SIGABRT Signal Forced Crash Information Disclosure Source: XF Type: UNKNOWN imapd-core(349) Source: XF Type: UNKNOWN imapd-core(349) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |