CVE-2007-4565NULL Pointer Dereference in Fetchmail

Severity
5.0MEDIUMNVD
EPSS
3.1%
top 13.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 28
Latest updateMay 1

Description

sink.c in fetchmail before 6.3.9 allows context-dependent attackers to cause a denial of service (NULL dereference and application crash) by refusing certain warning messages that are sent over SMTP.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/fetchmail< fetchmail 6.3.8-8 (bookworm)
Debianfetchmail/fetchmail< 6.3.8-8+2
NVDfetchmail/fetchmail6.3.9+101

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8x9c-m5v9-8766: sink2022-05-01
OSV
CVE-2007-4565: sink2007-08-28

📋Vendor Advisories

3
Ubuntu
fetchmail vulnerabilities2007-09-26
Red Hat
Fetchmail NULL pointer dereference2007-08-28
Debian
CVE-2007-4565: fetchmail - sink.c in fetchmail before 6.3.9 allows context-dependent attackers to cause a d...2007

💬Community

3
Bugzilla
CVE-2007-4565 Fetchmail NULL pointer dereference [FC6]2007-08-28
Bugzilla
CVE-2007-4565 Fetchmail NULL pointer dereference [F7]2007-08-28
Bugzilla
CVE-2007-4565 Fetchmail NULL pointer dereference2007-08-28
CVE-2007-4565 — NULL Pointer Dereference in Fetchmail | cvebase