CVE-2010-1167
fetchmail 4.6.3 through 6.3.16, when debug mode is enabled, does not properly handle invalid characters in a multi-character locale, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted (1)…
Does this matter?
Lower severity and a low EPSS score (2.20%). Track it; it rarely justifies an emergency change on its own.
Description
fetchmail 4.6.3 through 6.3.16, when debug mode is enabled, does not properly handle invalid characters in a multi-character locale, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted (1) message header or (2) POP3 UIDL list.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
- EPSS
- 2.20% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- fetchmail/fetchmail
- Source
- secalert@redhat.com
References
- http://developer.berlios.de/project/shownotes.php?group_id=1824&release_id=17512
- http://www.fetchmail.info/fetchmail-SA-2010-02.txtPatch
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:107
- http://www.securityfocus.com/archive/1/511140/100/0/threaded
- http://www.securityfocus.com/bid/39556
- http://developer.berlios.de/project/shownotes.php?group_id=1824&release_id=17512
- http://www.fetchmail.info/fetchmail-SA-2010-02.txtPatch
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:107
- http://www.securityfocus.com/archive/1/511140/100/0/threaded
- http://www.securityfocus.com/bid/39556
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.