Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-0562

Опубликовано: 08 фев. 2010
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

The sdump function in sdump.c in fetchmail 6.3.11, 6.3.12, and 6.3.13, when running in verbose mode on platforms for which char is signed, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an SSL X.509 certificate containing non-printable characters with the high bit set, which triggers a heap-based buffer overflow during escaping.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:fetchmail:fetchmail:6.3.11:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.3.12:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.3.13:*:*:*:*:*:*:*

EPSS

Процентиль: 82%
0.01751
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-119

Связанные уязвимости

ubuntu
почти 16 лет назад

The sdump function in sdump.c in fetchmail 6.3.11, 6.3.12, and 6.3.13, when running in verbose mode on platforms for which char is signed, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an SSL X.509 certificate containing non-printable characters with the high bit set, which triggers a heap-based buffer overflow during escaping.

redhat
почти 16 лет назад

The sdump function in sdump.c in fetchmail 6.3.11, 6.3.12, and 6.3.13, when running in verbose mode on platforms for which char is signed, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an SSL X.509 certificate containing non-printable characters with the high bit set, which triggers a heap-based buffer overflow during escaping.

debian
почти 16 лет назад

The sdump function in sdump.c in fetchmail 6.3.11, 6.3.12, and 6.3.13, ...

github
больше 3 лет назад

The sdump function in sdump.c in fetchmail 6.3.11, 6.3.12, and 6.3.13, when running in verbose mode on platforms for which char is signed, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an SSL X.509 certificate containing non-printable characters with the high bit set, which triggers a heap-based buffer overflow during escaping.

EPSS

Процентиль: 82%
0.01751
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-119