CVE-2003-0792Fetchmail vulnerability

CWE-3996 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
1.3%
top 19.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 17
Latest updateMay 3

Description

Fetchmail 6.2.4 and earlier does not properly allocate memory for long lines, which allows remote attackers to cause a denial of service (crash) via a certain email.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/fetchmail< fetchmail 6.2.5 (bookworm)
Debianfetchmail/fetchmail< 6.2.5+2
NVDfetchmail/fetchmail6.2.4+85

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rrh8-qpfq-g4g6: Fetchmail 62022-05-03
OSV
CVE-2003-0792: Fetchmail 62003-11-17

📋Vendor Advisories

2
Red Hat
security flaw2003-10-16
Debian
CVE-2003-0792: fetchmail - Fetchmail 6.2.4 and earlier does not properly allocate memory for long lines, wh...2003

💬Community

1
Bugzilla
CVE-2003-0792 security flaw2018-08-16
CVE-2003-0792 — Debian Fetchmail vulnerability | cvebase