PT-2012-4748 · Fetchmail+1 · Fetchmail+1

J. Porter Clark

+1

·

Publicado

2012-12-21

·

Atualizado

2024-06-15

·

CVE-2012-3482

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions Fetchmail versions 5.0.8 through 6.3.21
Description The issue allows remote NTLM servers to cause a denial of service, resulting in a crash and delayed delivery of inbound mail, via a crafted NTLM response that triggers an out-of-bounds read in the base64 decoder. Additionally, it enables remote NTLM servers to obtain sensitive information from memory via an NTLM Type 2 message with a crafted Target Name structure, which triggers an out-of-bounds read.
Recommendations For Fetchmail versions 5.0.8 through 6.3.21, consider disabling NTLM authentication in debug mode until a patch is available. Restrict access to the base64 decoder function to minimize the risk of exploitation. Avoid using the NTLM authentication protocol with debug mode enabled in the affected Fetchmail versions until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2012-3482
OPENSUSE-SU-2024:10194-1
SUSE-SU-2016:0872-1
SUSE-SU-2016_0872-1

Produtos afetados

Fetchmail
Suse