7.5
CVSSv2

CVE-2002-1365

Published: 23/12/2002 Updated: 03/05/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in Fetchmail 6.1.3 and previous versions does not account for the "@" character when determining buffer lengths for local addresses, which allows remote malicious users to execute arbitrary code via a header with a large number of local addresses.

Vulnerable Product Search on Vulmon Subscribe to Product

fetchmail fetchmail 6.1.0

fetchmail fetchmail 6.0.0

fetchmail fetchmail 5.8.13

fetchmail fetchmail 5.8.11

fetchmail fetchmail 5.7.2

fetchmail fetchmail 5.7.0

fetchmail fetchmail 5.4.5

fetchmail fetchmail 5.4.4

fetchmail fetchmail 5.2.4

fetchmail fetchmail 5.2.3

fetchmail fetchmail 5.0.6

fetchmail fetchmail 5.0.5

fetchmail fetchmail 4.7.6

fetchmail fetchmail 4.7.5

fetchmail fetchmail 4.6.7

fetchmail fetchmail 4.6.6

fetchmail fetchmail 4.5.8

fetchmail fetchmail 4.5.7

fetchmail fetchmail 5.9.0

fetchmail fetchmail 5.8.6

fetchmail fetchmail 5.7.4

fetchmail fetchmail 5.9.13

fetchmail fetchmail 5.9.11

fetchmail fetchmail 5.8.5

fetchmail fetchmail 5.8.4

fetchmail fetchmail 5.6.0

fetchmail fetchmail 5.5.6

fetchmail fetchmail 5.4.3

fetchmail fetchmail 5.3.8

fetchmail fetchmail 5.2.1

fetchmail fetchmail 5.2.0

fetchmail fetchmail 5.0.4

fetchmail fetchmail 5.0.3

fetchmail fetchmail 4.7.4

fetchmail fetchmail 4.7.3

fetchmail fetchmail 4.7.2

fetchmail fetchmail 4.6.5

fetchmail fetchmail 4.6.4

fetchmail fetchmail 4.5.6

fetchmail fetchmail 4.5.5

fetchmail fetchmail 5.8.17

fetchmail fetchmail 5.4.0

fetchmail fetchmail 5.9.5

fetchmail fetchmail 5.9.4

fetchmail fetchmail 5.8.14

fetchmail fetchmail 5.8.1

fetchmail fetchmail 5.8

fetchmail fetchmail 5.5.2

fetchmail fetchmail 5.5.0

fetchmail fetchmail 5.2.8

fetchmail fetchmail 5.2.7

fetchmail fetchmail 5.0.8

fetchmail fetchmail 5.0.7

fetchmail fetchmail 5.0.0

fetchmail fetchmail 4.7.7

fetchmail fetchmail 4.6.9

fetchmail fetchmail 4.6.8

fetchmail fetchmail 4.6.1

fetchmail fetchmail 4.6.0

fetchmail fetchmail 4.5.2

fetchmail fetchmail 4.5.1

fetchmail fetchmail 5.9.10

fetchmail fetchmail 5.9.8

fetchmail fetchmail 5.8.3

fetchmail fetchmail 5.8.2

fetchmail fetchmail 5.5.5

fetchmail fetchmail 5.5.3

fetchmail fetchmail 5.3.3

fetchmail fetchmail 5.3.1

fetchmail fetchmail 5.3.0

fetchmail fetchmail 5.1.4

fetchmail fetchmail 5.1.0

fetchmail fetchmail 5.0.2

fetchmail fetchmail 5.0.1

fetchmail fetchmail 4.7.1

fetchmail fetchmail 4.7.0

fetchmail fetchmail 4.6.3

fetchmail fetchmail 4.6.2

fetchmail fetchmail 4.5.4

fetchmail fetchmail 4.5.3

fetchmail fetchmail

Vendor Advisories

Stefan Esser of e-matters discovered a buffer overflow in fetchmail, an SSL enabled POP3, APOP and IMAP mail gatherer/forwarder When fetchmail retrieves a mail all headers that contain addresses are searched for local addresses If a hostname is missing, fetchmail appends it but doesn't reserve enough space for it This heap overflow can be used b ...