CVE-2008-2711
Publication date 16 June 2008
Last updated 24 July 2024
Ubuntu priority
fetchmail 6.3.8 and earlier, when running in -v -v (aka verbose) mode, allows remote attackers to cause a denial of service (crash and persistent mail failure) via a malformed mail message with long headers, which triggers an erroneous dereference when using vsnprintf to format log messages.
Status
Package | Ubuntu Release | Status |
---|---|---|
fetchmail | ||
Notes
jdstrand
per Debian, http://www.openwall.com/lists/oss-security/2008/06/13/1, -vv is only used for debugging purposes so this does not prevent a victim from getting mails. -vv is not used in non-interactive use.
Patch details
Package | Patch details |
---|---|
fetchmail |
|