VYPR
Unrated severityNVD Advisory· Published Mar 18, 2003· Updated Apr 16, 2026

CVE-2003-0143

CVE-2003-0143

Description

The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authenticated users to execute arbitrary code via a buffer overflow in a mdef command with a long macro name.

Affected products

4
  • Qualcomm/Qpopper4 versions
    cpe:2.3:a:qualcomm:qpopper:4.0.1:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:qualcomm:qpopper:4.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:qualcomm:qpopper:4.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:qualcomm:qpopper:4.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:qualcomm:qpopper:4.0.4:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.