PT-2012-4748 · Fetchmail+1 · Fetchmail+1
J. Porter Clark
+1
·
Published
2012-12-21
·
Updated
2024-06-15
·
CVE-2012-3482
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Fetchmail versions 5.0.8 through 6.3.21
Description
The issue allows remote NTLM servers to cause a denial of service, resulting in a crash and delayed delivery of inbound mail, via a crafted NTLM response that triggers an out-of-bounds read in the base64 decoder. Additionally, it enables remote NTLM servers to obtain sensitive information from memory via an NTLM Type 2 message with a crafted Target Name structure, which triggers an out-of-bounds read.
Recommendations
For Fetchmail versions 5.0.8 through 6.3.21, consider disabling NTLM authentication in debug mode until a patch is available. Restrict access to the base64 decoder function to minimize the risk of exploitation. Avoid using the NTLM authentication protocol with debug mode enabled in the affected Fetchmail versions until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fetchmail
Suse