5

CVE-2011-1947

fetchmail 5.9.9 through 6.3.19 does not properly limit the wait time after issuing a (1) STARTTLS or (2) STLS request, which allows remote servers to cause a denial of service (application hang) by acknowledging the request but not sending additional packets.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fetchmail ≫ Fetchmail Version 5.9.9
Fetchmail ≫ Fetchmail Version 5.9.10
Fetchmail ≫ Fetchmail Version 5.9.11
Fetchmail ≫ Fetchmail Version 5.9.13
Fetchmail ≫ Fetchmail Version 6.0.0
Fetchmail ≫ Fetchmail Version 6.1.0
Fetchmail ≫ Fetchmail Version 6.1.3
Fetchmail ≫ Fetchmail Version 6.2.0
Fetchmail ≫ Fetchmail Version 6.2.1
Fetchmail ≫ Fetchmail Version 6.2.2
Fetchmail ≫ Fetchmail Version 6.2.3
Fetchmail ≫ Fetchmail Version 6.2.4
Fetchmail ≫ Fetchmail Version 6.2.5
Fetchmail ≫ Fetchmail Version 6.2.5.1
Fetchmail ≫ Fetchmail Version 6.2.5.2
Fetchmail ≫ Fetchmail Version 6.2.5.4
Fetchmail ≫ Fetchmail Version 6.2.6 Update pre4
Fetchmail ≫ Fetchmail Version 6.2.6 Update pre8
Fetchmail ≫ Fetchmail Version 6.2.6 Update pre9
Fetchmail ≫ Fetchmail Version 6.2.9 Update rc10
Fetchmail ≫ Fetchmail Version 6.2.9 Update rc3
Fetchmail ≫ Fetchmail Version 6.2.9 Update rc4
Fetchmail ≫ Fetchmail Version 6.2.9 Update rc5
Fetchmail ≫ Fetchmail Version 6.2.9 Update rc7
Fetchmail ≫ Fetchmail Version 6.2.9 Update rc8
Fetchmail ≫ Fetchmail Version 6.2.9 Update rc9
Fetchmail ≫ Fetchmail Version 6.3.0
Fetchmail ≫ Fetchmail Version 6.3.1
Fetchmail ≫ Fetchmail Version 6.3.2
Fetchmail ≫ Fetchmail Version 6.3.3
Fetchmail ≫ Fetchmail Version 6.3.4
Fetchmail ≫ Fetchmail Version 6.3.5
Fetchmail ≫ Fetchmail Version 6.3.6
Fetchmail ≫ Fetchmail Version 6.3.6 Update rc1
Fetchmail ≫ Fetchmail Version 6.3.6 Update rc2
Fetchmail ≫ Fetchmail Version 6.3.6 Update rc3
Fetchmail ≫ Fetchmail Version 6.3.6 Update rc4
Fetchmail ≫ Fetchmail Version 6.3.6 Update rc5
Fetchmail ≫ Fetchmail Version 6.3.7
Fetchmail ≫ Fetchmail Version 6.3.8
Fetchmail ≫ Fetchmail Version 6.3.9
Fetchmail ≫ Fetchmail Version 6.3.9 Update rc2
Fetchmail ≫ Fetchmail Version 6.3.10
Fetchmail ≫ Fetchmail Version 6.3.11
Fetchmail ≫ Fetchmail Version 6.3.12
Fetchmail ≫ Fetchmail Version 6.3.13
Fetchmail ≫ Fetchmail Version 6.3.14
Fetchmail ≫ Fetchmail Version 6.3.15
Fetchmail ≫ Fetchmail Version 6.3.16
Fetchmail ≫ Fetchmail Version 6.3.17
Fetchmail ≫ Fetchmail Version 6.3.18
Fetchmail ≫ Fetchmail Version 6.3.19
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.55% 0.83
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.mandriva.com/security/advisories?name=MDVSA-2011:107
http://gitorious.org/fetchmail/fetchmail/blobs/legacy_63/fetchmail-SA-2011-01.txt
http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061634.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061672.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061735.html
http://openwall.com/lists/oss-security/2011/05/30/1
http://openwall.com/lists/oss-security/2011/05/31/12
http://openwall.com/lists/oss-security/2011/05/31/17
http://openwall.com/lists/oss-security/2011/06/01/2
http://www.fetchmail.info/fetchmail-SA-2011-01.txt
http://www.securityfocus.com/archive/1/518251/100/0/threaded
http://www.securityfocus.com/bid/48043
http://www.securitytracker.com/id?1025605
https://exchange.xforce.ibmcloud.com/vulnerabilities/67700