CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:N/I:N/A:P
EPSS
Percentile
95.2%
fetchmail 6.3.8 and earlier, when running in -v -v (aka verbose) mode,
allows remote attackers to cause a denial of service (crash and persistent
mail failure) via a malformed mail message with long headers, which
triggers an erroneous dereference when using vsnprintf to format log
messages.
Author | Note |
---|---|
jdstrand | per Debian, http://www.openwall.com/lists/oss-security/2008/06/13/1, -vv is only used for debugging purposes so this does not prevent a victim from getting mails. -vv is not used in non-interactive use. |