CVE-2004-0524
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/08/2004
Last modified:
03/04/2025
Description
Buffer overflow in the chpasswd command in the Change_passwd plugin before 4.0, as used in SquirrelMail, allows local users to gain root privileges via a long user name.
Impact
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:thiago_melo_de_paula:change_passwd:3.1.1.2.8:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://marc.info/?l=bugtraq&m=108222863917958&w=2
- http://marc.info/?l=bugtraq&m=108311782032370&w=2
- http://secunia.com/advisories/11415
- http://www.securityfocus.com/bid/10166
- http://www.squirrelmail.org/plugin_view.php?id=117
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15889
- http://marc.info/?l=bugtraq&m=108222863917958&w=2
- http://marc.info/?l=bugtraq&m=108311782032370&w=2
- http://secunia.com/advisories/11415
- http://www.securityfocus.com/bid/10166
- http://www.squirrelmail.org/plugin_view.php?id=117
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15889