Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-36386

Опубликовано: 28 июл. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.

A flaw was found in fetchmail. The flaw lies in how fetchmail when running in verbose mode using the -v flag tries to log long messages that are created from long headers. An attacker could potentially use this flaw to cause a Denial of Service attack or crash. The highest threat from this vulnerability is to data availability. This flaw was earlier identified by CVE-2008-2711 and fixed, however it recently got reintroduced due to a code refactoring issue. The current bug fix applies a different approach than the earlier one.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6fetchmailOut of support scope
Red Hat Enterprise Linux 7fetchmailOut of support scope
Red Hat Enterprise Linux 9fetchmailNot affected
Red Hat Enterprise Linux 8fetchmailFixedRHSA-2022:196410.05.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-665
https://bugzilla.redhat.com/show_bug.cgi?id=1987766fetchmail: DoS or information disclosure when logging long messages

EPSS

Процентиль: 43%
0.00203
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.

CVSS3: 7.5
nvd
почти 4 года назад

report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.

CVSS3: 7.5
debian
почти 4 года назад

report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits i ...

suse-cvrf
почти 4 года назад

Security update for fetchmail

suse-cvrf
почти 4 года назад

Security update for fetchmail

EPSS

Процентиль: 43%
0.00203
Низкий

7.5 High

CVSS3