5
CVSSv2

CVE-2005-2335

Published: 27/07/2005 Updated: 19/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Buffer overflow in the POP3 client in Fetchmail prior to 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute arbitrary code via long UIDL responses. NOTE: a typo in an advisory accidentally used the wrong CVE identifier for the Fetchmail issue. This is the correct identifier.

Vulnerable Product Search on Vulmon Subscribe to Product

fetchmail fetchmail 6.0.0

fetchmail fetchmail 5.9.13

fetchmail fetchmail 5.8.13

fetchmail fetchmail 5.8.11

fetchmail fetchmail 5.7.2

fetchmail fetchmail 5.7.0

fetchmail fetchmail 5.4.4

fetchmail fetchmail 5.4.3

fetchmail fetchmail 5.2.4

fetchmail fetchmail 5.2.3

fetchmail fetchmail 5.0.6

fetchmail fetchmail 5.0.5

fetchmail fetchmail 4.7.5

fetchmail fetchmail 4.7.4

fetchmail fetchmail 4.6.7

fetchmail fetchmail 4.6.6

fetchmail fetchmail 4.5.8

fetchmail fetchmail 4.5.7

fetchmail fetchmail 6.2.3

fetchmail fetchmail 5.9.11

fetchmail fetchmail 5.9.10

fetchmail fetchmail 5.8.5

fetchmail fetchmail 5.8.4

fetchmail fetchmail 5.6.0

fetchmail fetchmail 5.5.6

fetchmail fetchmail 5.3.8

fetchmail fetchmail 5.3.3

fetchmail fetchmail 5.2.1

fetchmail fetchmail 5.2.0

fetchmail fetchmail 5.0.4

fetchmail fetchmail 5.0.3

fetchmail fetchmail 5.0.2

fetchmail fetchmail 4.7.3

fetchmail fetchmail 4.7.2

fetchmail fetchmail 4.6.5

fetchmail fetchmail 4.6.4

fetchmail fetchmail 4.5.5

fetchmail fetchmail 4.5.4

fetchmail fetchmail 5.8.6

fetchmail fetchmail 5.7.4

fetchmail fetchmail 6.2.2

fetchmail fetchmail 5.9.8

fetchmail fetchmail 5.9.5

fetchmail fetchmail 5.8.3

fetchmail fetchmail 5.8.2

fetchmail fetchmail 5.5.5

fetchmail fetchmail 5.5.3

fetchmail fetchmail 5.5.2

fetchmail fetchmail 5.3.1

fetchmail fetchmail 5.3.0

fetchmail fetchmail 5.1.4

fetchmail fetchmail 5.1.0

fetchmail fetchmail 5.0.1

fetchmail fetchmail 5.0.0

fetchmail fetchmail 4.7.1

fetchmail fetchmail 4.7.0

fetchmail fetchmail 4.6.3

fetchmail fetchmail 4.6.2

fetchmail fetchmail 4.5.3

fetchmail fetchmail 4.5.2

fetchmail fetchmail 5.8.17

fetchmail fetchmail 6.3.4

fetchmail fetchmail 4.5.6

fetchmail fetchmail 6.2.4

fetchmail fetchmail 6.1.3

fetchmail fetchmail

fetchmail fetchmail 6.2.1

fetchmail fetchmail 6.2.0

fetchmail fetchmail 6.1.0

fetchmail fetchmail 5.9.4

fetchmail fetchmail 5.8.14

fetchmail fetchmail 5.8.1

fetchmail fetchmail 5.8

fetchmail fetchmail 5.5.0

fetchmail fetchmail 5.4.5

fetchmail fetchmail 5.2.8

fetchmail fetchmail 5.2.7

fetchmail fetchmail 5.0.8

fetchmail fetchmail 5.0.7

fetchmail fetchmail 4.7.7

fetchmail fetchmail 4.7.6

fetchmail fetchmail 4.6.9

fetchmail fetchmail 4.6.8

fetchmail fetchmail 4.6.1

fetchmail fetchmail 4.6.0

fetchmail fetchmail 4.5.1

fetchmail fetchmail 5.9.0

fetchmail fetchmail 5.4.0

fetchmail fetchmail 6.2.5

Vendor Advisories

Synopsis fetchmail security update Type/Severity Security Advisory: Important Topic Updated fetchmail packages that fix a security flaw are now availableThis update has been rated as having important security impact by the RedHat Security Response Team Description Fetchmail is a remote ma ...
Ross Boylan discovered a remote buffer overflow in fetchmail By sending invalid responses with very long UIDs, a faulty or malicious POP server could crash fetchmail or execute arbitrary code with the privileges of the user invoking fetchmail ...
Debian Bug report logs - #343836 (CVE-2005-4348) Security: DoS attack possible - crashes on empty message Package: fetchmail; Maintainer for fetchmail is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Source for fetchmail is src:fetchmail (PTS, buildd, popcon) Reported by: Steve Fosdick <dbugs@pelvouxnildramcouk> Date ...
Edward Shornock discovered a bug in the UIDL handling code of fetchmail, a common POP3, APOP and IMAP mail fetching utility A malicious POP3 server could exploit this problem and inject arbitrary code that will be executed on the victim host If fetchmail is running as root, this becomes a root exploit The old stable distribution (woody) is not a ...