Lucene search

K
cveMitreCVE-2001-1009
HistoryFeb 02, 2002 - 5:00 a.m.

CVE-2001-1009

2002-02-0205:00:00
CWE-264
mitre
web.nvd.nist.gov
25
cve-2001-1009
fetchmail-ssl
imap
pop/pop3
memory overwrite
privilege escalation

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.9

Confidence

High

EPSS

0.012

Percentile

85.5%

Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory and possibly gain privileges via a negative index number as part of a response to a LIST request.

Affected configurations

Nvd
Node
fetchmailfetchmailRange5.8.14
OR
fetchmailfetchmailMatch4.5.1
OR
fetchmailfetchmailMatch4.5.2
OR
fetchmailfetchmailMatch4.5.3
OR
fetchmailfetchmailMatch4.5.4
OR
fetchmailfetchmailMatch4.5.5
OR
fetchmailfetchmailMatch4.5.6
OR
fetchmailfetchmailMatch4.5.7
OR
fetchmailfetchmailMatch4.5.8
OR
fetchmailfetchmailMatch4.6.0
OR
fetchmailfetchmailMatch4.6.1
OR
fetchmailfetchmailMatch4.6.2
OR
fetchmailfetchmailMatch4.6.3
OR
fetchmailfetchmailMatch4.6.4
OR
fetchmailfetchmailMatch4.6.5
OR
fetchmailfetchmailMatch4.6.6
OR
fetchmailfetchmailMatch4.6.7
OR
fetchmailfetchmailMatch4.6.8
OR
fetchmailfetchmailMatch4.6.9
OR
fetchmailfetchmailMatch4.7.0
OR
fetchmailfetchmailMatch4.7.1
OR
fetchmailfetchmailMatch4.7.2
OR
fetchmailfetchmailMatch4.7.3
OR
fetchmailfetchmailMatch4.7.4
OR
fetchmailfetchmailMatch4.7.5
OR
fetchmailfetchmailMatch4.7.6
OR
fetchmailfetchmailMatch4.7.7
OR
fetchmailfetchmailMatch5.0.0
OR
fetchmailfetchmailMatch5.0.1
OR
fetchmailfetchmailMatch5.0.2
OR
fetchmailfetchmailMatch5.0.3
OR
fetchmailfetchmailMatch5.0.4
OR
fetchmailfetchmailMatch5.0.5
OR
fetchmailfetchmailMatch5.0.6
OR
fetchmailfetchmailMatch5.0.7
OR
fetchmailfetchmailMatch5.0.8
OR
fetchmailfetchmailMatch5.1.0
OR
fetchmailfetchmailMatch5.1.4
OR
fetchmailfetchmailMatch5.2.0
OR
fetchmailfetchmailMatch5.2.1
OR
fetchmailfetchmailMatch5.2.3
OR
fetchmailfetchmailMatch5.2.4
OR
fetchmailfetchmailMatch5.2.7
OR
fetchmailfetchmailMatch5.2.8
OR
fetchmailfetchmailMatch5.3.0
OR
fetchmailfetchmailMatch5.3.1
OR
fetchmailfetchmailMatch5.3.3
OR
fetchmailfetchmailMatch5.3.8
OR
fetchmailfetchmailMatch5.4.0
OR
fetchmailfetchmailMatch5.4.3
OR
fetchmailfetchmailMatch5.4.4
OR
fetchmailfetchmailMatch5.4.5
OR
fetchmailfetchmailMatch5.5.0
OR
fetchmailfetchmailMatch5.5.2
OR
fetchmailfetchmailMatch5.5.3
OR
fetchmailfetchmailMatch5.5.5
OR
fetchmailfetchmailMatch5.5.6
OR
fetchmailfetchmailMatch5.6.0
OR
fetchmailfetchmailMatch5.7.0
OR
fetchmailfetchmailMatch5.7.2
OR
fetchmailfetchmailMatch5.7.4
OR
fetchmailfetchmailMatch5.8
OR
fetchmailfetchmailMatch5.8.1
OR
fetchmailfetchmailMatch5.8.2
OR
fetchmailfetchmailMatch5.8.3
OR
fetchmailfetchmailMatch5.8.4
OR
fetchmailfetchmailMatch5.8.5
OR
fetchmailfetchmailMatch5.8.6
OR
fetchmailfetchmailMatch5.8.11
OR
fetchmailfetchmailMatch5.8.13
OR
fetchmailfetchmailMatch5.9.0
VendorProductVersionCPE
fetchmailfetchmail*cpe:2.3:a:fetchmail:fetchmail:*:*:*:*:*:*:*:*
fetchmailfetchmail4.5.1cpe:2.3:a:fetchmail:fetchmail:4.5.1:*:*:*:*:*:*:*
fetchmailfetchmail4.5.2cpe:2.3:a:fetchmail:fetchmail:4.5.2:*:*:*:*:*:*:*
fetchmailfetchmail4.5.3cpe:2.3:a:fetchmail:fetchmail:4.5.3:*:*:*:*:*:*:*
fetchmailfetchmail4.5.4cpe:2.3:a:fetchmail:fetchmail:4.5.4:*:*:*:*:*:*:*
fetchmailfetchmail4.5.5cpe:2.3:a:fetchmail:fetchmail:4.5.5:*:*:*:*:*:*:*
fetchmailfetchmail4.5.6cpe:2.3:a:fetchmail:fetchmail:4.5.6:*:*:*:*:*:*:*
fetchmailfetchmail4.5.7cpe:2.3:a:fetchmail:fetchmail:4.5.7:*:*:*:*:*:*:*
fetchmailfetchmail4.5.8cpe:2.3:a:fetchmail:fetchmail:4.5.8:*:*:*:*:*:*:*
fetchmailfetchmail4.6.0cpe:2.3:a:fetchmail:fetchmail:4.6.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 711

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.9

Confidence

High

EPSS

0.012

Percentile

85.5%