5

CVE-2002-1175

The getmxrecord function in Fetchmail 6.0.0 and earlier does not properly check the boundary of a particular malformed DNS packet from a malicious DNS server, which allows remote attackers to cause a denial of service (crash) when Fetchmail attempts to read data beyond the expected boundary.
Data is provided by the National Vulnerability Database (NVD)
FetchmailFetchmail Version <= 6.0.0
FetchmailFetchmail Version4.5.1
FetchmailFetchmail Version4.5.2
FetchmailFetchmail Version4.5.3
FetchmailFetchmail Version4.5.4
FetchmailFetchmail Version4.5.5
FetchmailFetchmail Version4.5.6
FetchmailFetchmail Version4.5.7
FetchmailFetchmail Version4.5.8
FetchmailFetchmail Version4.6.0
FetchmailFetchmail Version4.6.1
FetchmailFetchmail Version4.6.2
FetchmailFetchmail Version4.6.3
FetchmailFetchmail Version4.6.4
FetchmailFetchmail Version4.6.5
FetchmailFetchmail Version4.6.6
FetchmailFetchmail Version4.6.7
FetchmailFetchmail Version4.6.8
FetchmailFetchmail Version4.6.9
FetchmailFetchmail Version4.7.0
FetchmailFetchmail Version4.7.1
FetchmailFetchmail Version4.7.2
FetchmailFetchmail Version4.7.3
FetchmailFetchmail Version4.7.4
FetchmailFetchmail Version4.7.5
FetchmailFetchmail Version4.7.6
FetchmailFetchmail Version4.7.7
FetchmailFetchmail Version5.0.0
FetchmailFetchmail Version5.0.1
FetchmailFetchmail Version5.0.2
FetchmailFetchmail Version5.0.3
FetchmailFetchmail Version5.0.4
FetchmailFetchmail Version5.0.5
FetchmailFetchmail Version5.0.6
FetchmailFetchmail Version5.0.7
FetchmailFetchmail Version5.0.8
FetchmailFetchmail Version5.1.0
FetchmailFetchmail Version5.1.4
FetchmailFetchmail Version5.2.0
FetchmailFetchmail Version5.2.1
FetchmailFetchmail Version5.2.3
FetchmailFetchmail Version5.2.4
FetchmailFetchmail Version5.2.7
FetchmailFetchmail Version5.2.8
FetchmailFetchmail Version5.3.0
FetchmailFetchmail Version5.3.1
FetchmailFetchmail Version5.3.3
FetchmailFetchmail Version5.3.8
FetchmailFetchmail Version5.4.0
FetchmailFetchmail Version5.4.3
FetchmailFetchmail Version5.4.4
FetchmailFetchmail Version5.4.5
FetchmailFetchmail Version5.5.0
FetchmailFetchmail Version5.5.2
FetchmailFetchmail Version5.5.3
FetchmailFetchmail Version5.5.5
FetchmailFetchmail Version5.5.6
FetchmailFetchmail Version5.6.0
FetchmailFetchmail Version5.7.0
FetchmailFetchmail Version5.7.2
FetchmailFetchmail Version5.7.4
FetchmailFetchmail Version5.8
FetchmailFetchmail Version5.8.1
FetchmailFetchmail Version5.8.2
FetchmailFetchmail Version5.8.3
FetchmailFetchmail Version5.8.4
FetchmailFetchmail Version5.8.5
FetchmailFetchmail Version5.8.6
FetchmailFetchmail Version5.8.11
FetchmailFetchmail Version5.8.13
FetchmailFetchmail Version5.8.14
FetchmailFetchmail Version5.8.17
FetchmailFetchmail Version5.9.0
FetchmailFetchmail Version5.9.4
FetchmailFetchmail Version5.9.5
FetchmailFetchmail Version5.9.8
FetchmailFetchmail Version5.9.10
FetchmailFetchmail Version5.9.11
FetchmailFetchmail Version5.9.13
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.34% 0.782
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.