Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rr6c-95pp-cpgf

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.

report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.

EPSS

Процентиль: 43%
0.00203
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-909

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.

CVSS3: 7.5
redhat
почти 4 года назад

report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.

CVSS3: 7.5
nvd
почти 4 года назад

report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.

CVSS3: 7.5
debian
почти 4 года назад

report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits i ...

suse-cvrf
почти 4 года назад

Security update for fetchmail

EPSS

Процентиль: 43%
0.00203
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-909