Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2008-2711

Опубликовано: 16 июн. 2008
Источник: debian
EPSS Низкий

Описание

fetchmail 6.3.8 and earlier, when running in -v -v (aka verbose) mode, allows remote attackers to cause a denial of service (crash and persistent mail failure) via a malformed mail message with long headers, which triggers an erroneous dereference when using vsnprintf to format log messages.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
fetchmailfixed6.3.9~rc2-1package
fetchmailfixed6.3.6-1etch3etchpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2008/06/13/1

  • -vv is only used for debugging purposes so this does not

  • prevent a victim from getting mails. -vv is not used in non-interactive

  • use.

EPSS

Процентиль: 87%
0.03316
Низкий

Связанные уязвимости

ubuntu
около 17 лет назад

fetchmail 6.3.8 and earlier, when running in -v -v (aka verbose) mode, allows remote attackers to cause a denial of service (crash and persistent mail failure) via a malformed mail message with long headers, which triggers an erroneous dereference when using vsnprintf to format log messages.

redhat
около 17 лет назад

fetchmail 6.3.8 and earlier, when running in -v -v (aka verbose) mode, allows remote attackers to cause a denial of service (crash and persistent mail failure) via a malformed mail message with long headers, which triggers an erroneous dereference when using vsnprintf to format log messages.

nvd
около 17 лет назад

fetchmail 6.3.8 and earlier, when running in -v -v (aka verbose) mode, allows remote attackers to cause a denial of service (crash and persistent mail failure) via a malformed mail message with long headers, which triggers an erroneous dereference when using vsnprintf to format log messages.

github
около 3 лет назад

fetchmail 6.3.8 and earlier, when running in -v -v (aka verbose) mode, allows remote attackers to cause a denial of service (crash and persistent mail failure) via a malformed mail message with long headers, which triggers an erroneous dereference when using vsnprintf to format log messages.

oracle-oval
почти 16 лет назад

ELSA-2009-1427: fetchmail security update (MODERATE)

EPSS

Процентиль: 87%
0.03316
Низкий