6.4
CVSSv2

CVE-2009-2666

Published: 07/08/2009 Updated: 10/10/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

socket.c in fetchmail prior to 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle malicious users to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Vulnerable Product Search on Vulmon Subscribe to Product

fetchmail fetchmail 6.3.5

fetchmail fetchmail 6.3.3

fetchmail fetchmail 6.2.5.4

fetchmail fetchmail 6.2.6

fetchmail fetchmail 6.2.0

fetchmail fetchmail 6.1.0

fetchmail fetchmail 5.9.4

fetchmail fetchmail 5.8.14

fetchmail fetchmail 5.8.13

fetchmail fetchmail 5.8

fetchmail fetchmail 5.7.2

fetchmail fetchmail 5.5.0

fetchmail fetchmail 5.4.5

fetchmail fetchmail 5.2.7

fetchmail fetchmail 5.2.4

fetchmail fetchmail 5.0.7

fetchmail fetchmail 5.0.6

fetchmail fetchmail 4.7.7

fetchmail fetchmail 4.7.6

fetchmail fetchmail 4.6.8

fetchmail fetchmail 4.6.7

fetchmail fetchmail 4.6.0

fetchmail fetchmail 4.5.8

fetchmail fetchmail 4.5.1

fetchmail fetchmail 5.9.0

fetchmail fetchmail 5.7.4

fetchmail fetchmail 5.8.17

fetchmail fetchmail 6.3.6

fetchmail fetchmail 6.2.5.2

fetchmail fetchmail 6.3.0

fetchmail fetchmail 6.3.2

fetchmail fetchmail 6.3.1

fetchmail fetchmail 6.2.9

fetchmail fetchmail 6.0.0

fetchmail fetchmail 5.9.13

fetchmail fetchmail 5.8.11

fetchmail fetchmail 5.8.5

fetchmail fetchmail 5.7.0

fetchmail fetchmail 5.6.0

fetchmail fetchmail 5.4.4

fetchmail fetchmail 5.4.3

fetchmail fetchmail 5.2.3

fetchmail fetchmail 5.2.1

fetchmail fetchmail 5.0.5

fetchmail fetchmail 5.0.4

fetchmail fetchmail 4.7.5

fetchmail fetchmail 4.7.4

fetchmail fetchmail 4.6.6

fetchmail fetchmail 4.6.5

fetchmail fetchmail 4.5.7

fetchmail fetchmail 4.5.6

fetchmail fetchmail 6.2.5.1

fetchmail fetchmail 6.3.4

fetchmail fetchmail 6.3.8

fetchmail fetchmail 6.2.5

fetchmail fetchmail 6.2.3

fetchmail fetchmail 5.9.11

fetchmail fetchmail 5.9.10

fetchmail fetchmail 5.8.4

fetchmail fetchmail 5.8.3

fetchmail fetchmail 5.5.6

fetchmail fetchmail 5.5.5

fetchmail fetchmail 5.3.8

fetchmail fetchmail 5.3.3

fetchmail fetchmail 5.2.0

fetchmail fetchmail 5.1.4

fetchmail fetchmail 5.0.3

fetchmail fetchmail 5.0.2

fetchmail fetchmail 4.7.3

fetchmail fetchmail 4.7.2

fetchmail fetchmail 4.7.1

fetchmail fetchmail 4.6.4

fetchmail fetchmail 4.6.3

fetchmail fetchmail 4.5.5

fetchmail fetchmail 4.5.4

fetchmail fetchmail 6.2.4

fetchmail fetchmail 5.4.0

fetchmail fetchmail 6.3.9

fetchmail fetchmail 6.3.7

fetchmail fetchmail 6.2.2

fetchmail fetchmail 6.2.1

fetchmail fetchmail 5.9.8

fetchmail fetchmail 5.9.5

fetchmail fetchmail 5.8.2

fetchmail fetchmail 5.8.1

fetchmail fetchmail 5.5.3

fetchmail fetchmail 5.5.2

fetchmail fetchmail 5.3.1

fetchmail fetchmail 5.3.0

fetchmail fetchmail 5.2.8

fetchmail fetchmail 5.1.0

fetchmail fetchmail 5.0.8

fetchmail fetchmail 5.0.1

fetchmail fetchmail 5.0.0

fetchmail fetchmail 4.7.0

fetchmail fetchmail 4.6.9

fetchmail fetchmail 4.6.2

fetchmail fetchmail 4.6.1

fetchmail fetchmail 4.5.3

fetchmail fetchmail 4.5.2

fetchmail fetchmail 6.1.3

fetchmail fetchmail 5.8.6

fetchmail fetchmail

Vendor Advisories

Matthias Andree discovered that fetchmail did not properly handle certificates with NULL characters in the certificate name A remote attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications ...
It was discovered that fetchmail, a full-featured remote mail retrieval and forwarding utility, is vulnerable to the "Null Prefix Attacks Against SSL/TLS Certificates" recently published at the Blackhat conference This allows an attacker to perform undetected man-in-the-middle attacks via a crafted ITU-T X509 certificate with an injected null byt ...

Github Repositories

补丁管理报告 补丁管理摘要 网络范围 19216811-1921681255 补丁安装状态 数量 高危 重要 中等 一般 低 已安装补丁 0 0 0 0 0 0 未安装补丁 140 32 47 14 3 44 小计 140 32 47 15 3 44 高危等级补丁 CESA-2011:0436_ CESA-2011:0844_ CESA-2011:0999_ 重要等级补丁 CESA-2011:0436_ CESA-2011:0844_ CESA-2011:0999