Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authenticated users to execute arbitrary code via a buffer overflow in a mdef command with a long macro name.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Qpopper远程内存损坏漏洞
Vulnerability Description
Qpopper 4.0.5fc2之前4.0.x版本的pop_msg函数在Qvsnprintf调用消息缓冲区后没有将其空终止,认证用户可以借助带有超长宏名称的mdef命令的缓冲区溢出执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A