5.8
CVSSv2

CVE-2012-3482

Published: 21/12/2012 Updated: 05/04/2013
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P

Vulnerability Summary

Fetchmail 5.0.8 up to and including 6.3.21, when using NTLM authentication in debug mode, allows remote NTLM servers to (1) cause a denial of service (crash and delayed delivery of inbound mail) via a crafted NTLM response that triggers an out-of-bounds read in the base64 decoder, or (2) obtain sensitive information from memory via an NTLM Type 2 message with a crafted Target Name structure, which triggers an out-of-bounds read.

Vulnerable Product Search on Vulmon Subscribe to Product

fetchmail fetchmail 5.2.4

fetchmail fetchmail 5.2.7

fetchmail fetchmail 5.2.8

fetchmail fetchmail 5.4.4

fetchmail fetchmail 5.4.5

fetchmail fetchmail 5.7.0

fetchmail fetchmail 5.7.2

fetchmail fetchmail 5.8.2

fetchmail fetchmail 5.8.3

fetchmail fetchmail 5.9.13

fetchmail fetchmail 5.9.4

fetchmail fetchmail 6.3.14

fetchmail fetchmail 6.3.13

fetchmail fetchmail 6.3.6

fetchmail fetchmail 6.2.9

fetchmail fetchmail 6.2.6

fetchmail fetchmail 6.3.7

fetchmail fetchmail 6.3.5

fetchmail fetchmail 6.3.4

fetchmail fetchmail 6.2.1

fetchmail fetchmail 6.0.0

fetchmail fetchmail 5.2.1

fetchmail fetchmail 5.2.3

fetchmail fetchmail 5.4.0

fetchmail fetchmail 5.4.3

fetchmail fetchmail 5.5.6

fetchmail fetchmail 5.6.0

fetchmail fetchmail 5.8.13

fetchmail fetchmail 5.8.14

fetchmail fetchmail 5.8.17

fetchmail fetchmail 5.9.10

fetchmail fetchmail 5.9.11

fetchmail fetchmail 6.3.18

fetchmail fetchmail 6.2.4

fetchmail fetchmail 6.3.16

fetchmail fetchmail 6.3.11

fetchmail fetchmail 6.3.8

fetchmail fetchmail 6.2.5

fetchmail fetchmail 6.1.0

fetchmail fetchmail 6.2.2

fetchmail fetchmail 5.1.0

fetchmail fetchmail 5.2.0

fetchmail fetchmail 5.3.3

fetchmail fetchmail 5.3.8

fetchmail fetchmail 5.5.3

fetchmail fetchmail 5.5.5

fetchmail fetchmail 5.8.1

fetchmail fetchmail 5.8.11

fetchmail fetchmail 5.8.6

fetchmail fetchmail 5.9.0

fetchmail fetchmail 6.1.3

fetchmail fetchmail 6.3.19

fetchmail fetchmail 6.3.12

fetchmail fetchmail 6.3.10

fetchmail fetchmail 6.3.9

fetchmail fetchmail 6.2.3

fetchmail fetchmail 6.2.5.1

fetchmail fetchmail 6.2.0

fetchmail fetchmail 6.3.1

fetchmail fetchmail 5.0.8

fetchmail fetchmail 5.1.4

fetchmail fetchmail 5.3.0

fetchmail fetchmail 5.3.1

fetchmail fetchmail 5.5.0

fetchmail fetchmail 5.5.2

fetchmail fetchmail 5.7.4

fetchmail fetchmail 5.8

fetchmail fetchmail 5.8.4

fetchmail fetchmail 5.8.5

fetchmail fetchmail 5.9.5

fetchmail fetchmail 5.9.8

fetchmail fetchmail 6.3.17

fetchmail fetchmail 6.3.15

fetchmail fetchmail 6.3.0

fetchmail fetchmail 6.2.5.4

fetchmail fetchmail 6.2.5.2

fetchmail fetchmail 6.3.3

fetchmail fetchmail 6.3.2

fetchmail fetchmail 6.3.21

Vendor Advisories

Fetchmail 508 through 6321, when using NTLM authentication in debug mode, allows remote NTLM servers to (1) cause a denial of service (crash and delayed delivery of inbound mail) via a crafted NTLM response that triggers an out-of-bounds read in the base64 decoder, or (2) obtain sensitive information from memory via an NTLM Type 2 message with ...