7.8

CVE-2006-5867

fetchmail before 6.3.6-rc4 does not properly enforce TLS and may transmit cleartext passwords over unsecured links if certain circumstances occur, which allows remote attackers to obtain sensitive information via man-in-the-middle (MITM) attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fetchmail ≫ Fetchmail Update rc3 Version <= 6.3.6
Fetchmail ≫ Fetchmail Version 4.5.1
Fetchmail ≫ Fetchmail Version 4.5.2
Fetchmail ≫ Fetchmail Version 4.5.3
Fetchmail ≫ Fetchmail Version 4.5.4
Fetchmail ≫ Fetchmail Version 4.5.5
Fetchmail ≫ Fetchmail Version 4.5.6
Fetchmail ≫ Fetchmail Version 4.5.7
Fetchmail ≫ Fetchmail Version 4.5.8
Fetchmail ≫ Fetchmail Version 4.6.0
Fetchmail ≫ Fetchmail Version 4.6.1
Fetchmail ≫ Fetchmail Version 4.6.2
Fetchmail ≫ Fetchmail Version 4.6.3
Fetchmail ≫ Fetchmail Version 4.6.4
Fetchmail ≫ Fetchmail Version 4.6.5
Fetchmail ≫ Fetchmail Version 4.6.6
Fetchmail ≫ Fetchmail Version 4.6.7
Fetchmail ≫ Fetchmail Version 4.6.8
Fetchmail ≫ Fetchmail Version 4.6.9
Fetchmail ≫ Fetchmail Version 4.7.0
Fetchmail ≫ Fetchmail Version 4.7.1
Fetchmail ≫ Fetchmail Version 4.7.2
Fetchmail ≫ Fetchmail Version 4.7.3
Fetchmail ≫ Fetchmail Version 4.7.4
Fetchmail ≫ Fetchmail Version 4.7.5
Fetchmail ≫ Fetchmail Version 4.7.6
Fetchmail ≫ Fetchmail Version 4.7.7
Fetchmail ≫ Fetchmail Version 5.0.0
Fetchmail ≫ Fetchmail Version 5.0.1
Fetchmail ≫ Fetchmail Version 5.0.2
Fetchmail ≫ Fetchmail Version 5.0.3
Fetchmail ≫ Fetchmail Version 5.0.4
Fetchmail ≫ Fetchmail Version 5.0.5
Fetchmail ≫ Fetchmail Version 5.0.6
Fetchmail ≫ Fetchmail Version 5.0.7
Fetchmail ≫ Fetchmail Version 5.0.8
Fetchmail ≫ Fetchmail Version 5.1.0
Fetchmail ≫ Fetchmail Version 5.1.4
Fetchmail ≫ Fetchmail Version 5.2.0
Fetchmail ≫ Fetchmail Version 5.2.1
Fetchmail ≫ Fetchmail Version 5.2.3
Fetchmail ≫ Fetchmail Version 5.2.4
Fetchmail ≫ Fetchmail Version 5.2.7
Fetchmail ≫ Fetchmail Version 5.2.8
Fetchmail ≫ Fetchmail Version 5.3.0
Fetchmail ≫ Fetchmail Version 5.3.1
Fetchmail ≫ Fetchmail Version 5.3.3
Fetchmail ≫ Fetchmail Version 5.3.8
Fetchmail ≫ Fetchmail Version 5.4.0
Fetchmail ≫ Fetchmail Version 5.4.3
Fetchmail ≫ Fetchmail Version 5.4.4
Fetchmail ≫ Fetchmail Version 5.4.5
Fetchmail ≫ Fetchmail Version 5.5.0
Fetchmail ≫ Fetchmail Version 5.5.2
Fetchmail ≫ Fetchmail Version 5.5.3
Fetchmail ≫ Fetchmail Version 5.5.5
Fetchmail ≫ Fetchmail Version 5.5.6
Fetchmail ≫ Fetchmail Version 5.6.0
Fetchmail ≫ Fetchmail Version 5.7.0
Fetchmail ≫ Fetchmail Version 5.7.2
Fetchmail ≫ Fetchmail Version 5.7.4
Fetchmail ≫ Fetchmail Version 5.8
Fetchmail ≫ Fetchmail Version 5.8.1
Fetchmail ≫ Fetchmail Version 5.8.2
Fetchmail ≫ Fetchmail Version 5.8.3
Fetchmail ≫ Fetchmail Version 5.8.4
Fetchmail ≫ Fetchmail Version 5.8.5
Fetchmail ≫ Fetchmail Version 5.8.6
Fetchmail ≫ Fetchmail Version 5.8.11
Fetchmail ≫ Fetchmail Version 5.8.13
Fetchmail ≫ Fetchmail Version 5.8.14
Fetchmail ≫ Fetchmail Version 5.8.17
Fetchmail ≫ Fetchmail Version 5.9.0
Fetchmail ≫ Fetchmail Version 5.9.4
Fetchmail ≫ Fetchmail Version 5.9.5
Fetchmail ≫ Fetchmail Version 5.9.8
Fetchmail ≫ Fetchmail Version 5.9.10
Fetchmail ≫ Fetchmail Version 5.9.11
Fetchmail ≫ Fetchmail Version 5.9.13
Fetchmail ≫ Fetchmail Version 6.0.0
Fetchmail ≫ Fetchmail Version 6.1.0
Fetchmail ≫ Fetchmail Version 6.1.3
Fetchmail ≫ Fetchmail Version 6.2.0
Fetchmail ≫ Fetchmail Version 6.2.1
Fetchmail ≫ Fetchmail Version 6.2.2
Fetchmail ≫ Fetchmail Version 6.2.3
Fetchmail ≫ Fetchmail Version 6.2.4
Fetchmail ≫ Fetchmail Version 6.2.5
Fetchmail ≫ Fetchmail Version 6.2.5.1
Fetchmail ≫ Fetchmail Version 6.2.5.2
Fetchmail ≫ Fetchmail Version 6.2.5.4
Fetchmail ≫ Fetchmail Version 6.2.6 Update pre4
Fetchmail ≫ Fetchmail Version 6.2.6 Update pre8
Fetchmail ≫ Fetchmail Version 6.2.6 Update pre9
Fetchmail ≫ Fetchmail Version 6.2.9 Update rc10
Fetchmail ≫ Fetchmail Version 6.2.9 Update rc3
Fetchmail ≫ Fetchmail Version 6.2.9 Update rc4
Fetchmail ≫ Fetchmail Version 6.2.9 Update rc5
Fetchmail ≫ Fetchmail Version 6.2.9 Update rc7
Fetchmail ≫ Fetchmail Version 6.2.9 Update rc8
Fetchmail ≫ Fetchmail Version 6.2.9 Update rc9
Fetchmail ≫ Fetchmail Version 6.3.0
Fetchmail ≫ Fetchmail Version 6.3.1
Fetchmail ≫ Fetchmail Version 6.3.2
Fetchmail ≫ Fetchmail Version 6.3.3
Fetchmail ≫ Fetchmail Version 6.3.4
Fetchmail ≫ Fetchmail Version 6.3.5
Fetchmail ≫ Fetchmail Version 6.3.6 Update rc1
Fetchmail ≫ Fetchmail Version 6.3.6 Update rc2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.39% 0.904
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 10 6.9
AV:N/AC:L/Au:N/C:C/I:N/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc
http://secunia.com/advisories/24007
Vendor Advisory
http://secunia.com/advisories/24284
Vendor Advisory
http://www.novell.com/linux/security/advisories/2007_4_sr.html
http://www.redhat.com/support/errata/RHSA-2007-0018.html
http://docs.info.apple.com/article.html?artnum=305391
http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html
http://secunia.com/advisories/24966
Vendor Advisory
http://www.us-cert.gov/cas/techalerts/TA07-109A.html
US Government Resource
http://www.vupen.com/english/advisories/2007/1470
http://fedoranews.org/cms/node/2429
http://fetchmail.berlios.de/fetchmail-SA-2006-02.txt
http://osvdb.org/31580
http://secunia.com/advisories/23631
Vendor Advisory
http://secunia.com/advisories/23695
Vendor Advisory
http://secunia.com/advisories/23714
Vendor Advisory
http://secunia.com/advisories/23781
Vendor Advisory
http://secunia.com/advisories/23804
Vendor Advisory
http://secunia.com/advisories/23838
Vendor Advisory
http://secunia.com/advisories/23923
Vendor Advisory
http://secunia.com/advisories/24151
Vendor Advisory
http://secunia.com/advisories/24174
Vendor Advisory
http://security.gentoo.org/glsa/glsa-200701-13.xml
http://securitytracker.com/id?1017478
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.517995
http://www.debian.org/security/2007/dsa-1259
http://www.mandriva.com/security/advisories?name=MDKSA-2007:016
http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.004.html
http://www.securityfocus.com/archive/1/456115/100/0/threaded
http://www.securityfocus.com/archive/1/460528/100/0/threaded
http://www.securityfocus.com/bid/21903
Patch
http://www.trustix.org/errata/2007/0007
http://www.ubuntu.com/usn/usn-405-1
http://www.vupen.com/english/advisories/2007/0087
http://www.vupen.com/english/advisories/2007/0088
https://issues.rpath.com/browse/RPL-919
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10566