PT-2008-4156 · Fetchmail+1 · Fetchmail+1

Publicado

2008-06-16

·

Atualizado

2021-08-09

·

CVE-2008-2711

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions fetchmail versions 6.3.8 and earlier
Description The issue allows remote attackers to cause a denial of service, resulting in a crash and persistent mail failure. This is achieved by sending a malformed mail message with long headers, which triggers an erroneous dereference when using vsnprintf to format log messages. The attack is possible when fetchmail is running in verbose mode.
Recommendations For fetchmail versions 6.3.8 and earlier, avoid running in verbose mode until a fix is available. As a temporary workaround, consider disabling the verbose mode to minimize the risk of exploitation.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-2711
RHSA-2009:1427
RHSA-2009_1427

Produtos afetados

Red Hat
Fetchmail