PT-2005-3261 · Fetchmail+1 · Fetchmail+1
Edward Shornock
·
Published
2005-07-25
·
Updated
2018-10-19
·
CVE-2005-2335
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Fetchmail versions prior to 6.2.5.2
Description
The issue is related to a buffer overflow in the POP3 client, which can be triggered by remote POP3 servers sending long UIDL responses. This can cause a denial of service and potentially allow the execution of arbitrary code.
Recommendations
For Fetchmail versions prior to 6.2.5.2, update to version 6.2.5.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the POP3 client to minimize the risk of exploitation.
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fetchmail
Red Hat