Lucene search

K
freebsdFreeBSDF7EB0B23-7099-11DA-A15C-0060084A00E5
HistoryDec 19, 2005 - 12:00 a.m.

fetchmail -- null pointer dereference in multidrop mode with headerless email

2005-12-1900:00:00
vuxml.freebsd.org
18

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.079

Percentile

94.3%

The fetchmail team reports:

Fetchmail contains a bug that causes an application crash
when fetchmail is configured for multidrop mode and the
upstream mail server sends a message without headers. As
fetchmail does not record this message as “previously fetched”,
it will crash with the same message if it is re-executed, so it
cannot make progress. A malicious or broken-into upstream server
could thus cause a denial of service in fetchmail clients.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchfetchmail< 6.3.1UNKNOWN

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.079

Percentile

94.3%