GEN:SID 1:1934
Message POP2 FOLD overflow attempt
Summary This event is generated when an attempt is made to exploit a buffer
overflow condition in the Post Office Protocol (POP) command FOLD.
Impact Possible remote execution of arbitrary code leading to a remote root
compromise.
Detailed Information A vulnerability exists such that an attacker may overflow a buffer by
sending data where a line feed character should occur to a POP server
via the FOLD command.

The FOLD command allows the user to specify a mail folder to select.  By
specifying a very large argument, the user can exploit the buffer overflow
condition.
Affected Systems  
Attack Scenarios Simple. An attacker can supply specially crafted packets to a POP server
via the FOLD function.
Ease of Attack Simple.
Corrective Action Upgrade to the latest non-affected version of the software.
Additional References  
Rule References bugtraq: 283
cve: 1999-0920
nessus: 10130