PT-2010-2879 · Fetchmail · Fetchmail
Published
2010-05-07
·
Updated
2024-06-15
·
CVE-2010-1167
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
fetchmail versions 4.6.3 through 6.3.16
Description
The issue allows remote attackers to cause a denial of service, resulting in memory consumption and application crash, by sending a crafted message header or POP3 UIDL list when debug mode is enabled. This occurs due to improper handling of invalid characters in a multi-character locale.
Recommendations
For fetchmail versions 4.6.3 through 6.3.16, consider disabling debug mode to prevent exploitation until a patch is available.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fetchmail