CVE-2005-4348Fetchmail vulnerability

CWE-3999 documents7 sources
Severity
7.8HIGHNVD
EPSS
10.0%
top 6.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 21
Latest updateMay 3

Description

fetchmail before 6.3.1 and before 6.2.5.5, when configured for multidrop mode, allows remote attackers to cause a denial of service (application crash) by sending messages without headers from upstream mail servers.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages3 packages

debiandebian/fetchmail< fetchmail 6.3.1-1 (bookworm)
NVDfetchmail/fetchmail6.2.06.2.5.5+1
Debianfetchmail/fetchmail< 6.3.1-1+2

🔴Vulnerability Details

2
GHSA
GHSA-5g7c-7whj-r862: fetchmail before 62022-05-03
OSV
CVE-2005-4348: fetchmail before 62005-12-21

📋Vendor Advisories

3
Ubuntu
fetchmail vulnerability2006-01-03
Red Hat
security flaw2005-12-19
Debian
CVE-2005-4348: fetchmail - fetchmail before 6.3.1 and before 6.2.5.5, when configured for multidrop mode, a...2005

💬Community

3
Bugzilla
CVE-2005-4348 security flaw2018-08-16
Bugzilla
CVE-2005-4348 Fetchmail DOS by malicious server in multidrop mode2005-12-20
Bugzilla
CVE-2005-4348 Fetchmail DOS by malicious server in multidrop mode2005-12-20
CVE-2005-4348 — Fetchmail vulnerability | cvebase