CVE-2006-5974Improper Input Validation in Fetchmail

Severity
7.8HIGHNVD
EPSS
13.8%
top 5.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 31
Latest updateMay 1

Description

fetchmail 6.3.5 and 6.3.6 before 6.3.6-rc4, when refusing a message delivered via the mda option, allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger a NULL pointer dereference when calling the (1) ferror or (2) fflush functions.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages3 packages

debiandebian/fetchmail< fetchmail 6.3.6-1 (bookworm)
Debianfetchmail/fetchmail< 6.3.6-1+2
NVDfetchmail/fetchmail6.3.5, 6.3.6+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-qjgr-cmw7-hw63: fetchmail 62022-05-01
OSV
CVE-2006-5974: fetchmail 62006-12-31

📋Vendor Advisories

2
Debian
CVE-2006-5974: fetchmail - fetchmail 6.3.5 and 6.3.6 before 6.3.6-rc4, when refusing a message delivered vi...2006
Red Hat
CVE-2006-5974: fetchmail 6
CVE-2006-5974 — Improper Input Validation in Fetchmail | cvebase