PT-2008-4156 · Fetchmail+1 · Fetchmail+1
Publicado
2008-06-16
·
Atualizado
2021-08-09
·
CVE-2008-2711
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
fetchmail versions 6.3.8 and earlier
Description
The issue allows remote attackers to cause a denial of service, resulting in a crash and persistent mail failure. This is achieved by sending a malformed mail message with long headers, which triggers an erroneous dereference when using vsnprintf to format log messages. The attack is possible when fetchmail is running in verbose mode.
Recommendations
For fetchmail versions 6.3.8 and earlier, avoid running in verbose mode until a fix is available. As a temporary workaround, consider disabling the verbose mode to minimize the risk of exploitation.
Correção
DoS
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat
Fetchmail