vendor:
Fetchmail
by:
Salvatore Sanfilippo
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Fetchmail
Affected Version From: 5.8.15
Affected Version To: 5.8.15
Patch Exists: YES
Related CWE: N/A
CPE: a:fetchmail:fetchmail
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2001
Fetchmail Remote Buffer Overflow Vulnerability
Fetchmail is a unix utility for downloading email from mail servers via POP3 and IMAP. Fetchmail contains a vulnerability that may allow for remote attackers to gain access to client systems. The vulnerability has to do with the use of a remotely supplied signed integer value as the index to an array when writing data to memory. It is be possible for attackers to overwrite critical variables in memory with arbitrary values if the target client's IMAP server can be impersonated. Successful exploitation can lead to the exectution of arbitrary code on the client host.
Mitigation:
Upgrade to the latest version of Fetchmail, or apply the patch provided by the vendor.