CVE-2005-2335

Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute arbitrary code via long UIDL responses. NOTE: a typo in an advisory accidentally used the wrong CVE identifier for the Fetchmail issue. This is the correct identifier.
References
Link Resource
http://developer.berlios.de/project/shownotes.php?release_id=6617 Patch
http://fetchmail.berlios.de/fetchmail-SA-2005-01.txt Patch Vendor Advisory
http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html
http://secunia.com/advisories/16176 Vendor Advisory
http://secunia.com/advisories/21253 Vendor Advisory
http://www.debian.org/security/2005/dsa-774
http://www.novell.com/linux/security/advisories/2005_18_sr.html
http://www.osvdb.org/18174
http://www.redhat.com/archives/fedora-announce-list/2005-July/msg00088.html
http://www.redhat.com/archives/fedora-announce-list/2005-July/msg00089.html Patch
http://www.redhat.com/archives/fedora-announce-list/2005-July/msg00104.html
http://www.redhat.com/support/errata/RHSA-2005-640.html
http://www.securityfocus.com/archive/1/435197/100/0/threaded
http://www.securityfocus.com/archive/1/441856/100/200/threaded
http://www.securityfocus.com/bid/14349 Patch
http://www.securityfocus.com/bid/19289
http://www.us-cert.gov/cas/techalerts/TA06-214A.html US Government Resource
http://www.vupen.com/english/advisories/2005/1171
http://www.vupen.com/english/advisories/2006/3101
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1038
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1124
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8833
http://developer.berlios.de/project/shownotes.php?release_id=6617 Patch
http://fetchmail.berlios.de/fetchmail-SA-2005-01.txt Patch Vendor Advisory
http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html
http://secunia.com/advisories/16176 Vendor Advisory
http://secunia.com/advisories/21253 Vendor Advisory
http://www.debian.org/security/2005/dsa-774
http://www.novell.com/linux/security/advisories/2005_18_sr.html
http://www.osvdb.org/18174
http://www.redhat.com/archives/fedora-announce-list/2005-July/msg00088.html
http://www.redhat.com/archives/fedora-announce-list/2005-July/msg00089.html Patch
http://www.redhat.com/archives/fedora-announce-list/2005-July/msg00104.html
http://www.redhat.com/support/errata/RHSA-2005-640.html
http://www.securityfocus.com/archive/1/435197/100/0/threaded
http://www.securityfocus.com/archive/1/441856/100/200/threaded
http://www.securityfocus.com/bid/14349 Patch
http://www.securityfocus.com/bid/19289
http://www.us-cert.gov/cas/techalerts/TA06-214A.html US Government Resource
http://www.vupen.com/english/advisories/2005/1171
http://www.vupen.com/english/advisories/2006/3101
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1038
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1124
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8833
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fetchmail:fetchmail:*:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.5.1:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.5.2:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.5.3:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.5.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.5.5:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.5.6:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.5.7:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.5.8:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.1:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.2:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.3:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.5:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.6:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.7:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.8:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.9:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.7.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.7.1:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.7.2:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.7.3:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.7.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.7.5:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.7.6:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.7.7:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.0.2:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.0.3:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.0.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.0.5:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.0.6:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.0.7:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.0.8:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.1.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.1.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.2.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.2.1:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.2.3:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.2.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.2.7:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.2.8:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.3.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.3.1:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.3.3:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.3.8:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.4.3:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.4.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.4.5:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.5.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.5.2:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.5.3:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.5.5:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.5.6:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.6.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.7.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.7.2:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.7.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.8:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.8.1:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.8.2:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.8.3:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.8.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.8.5:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.8.6:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.8.11:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.8.13:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.8.14:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.8.17:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.9.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.9.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.9.5:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.9.8:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.9.10:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.9.11:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.9.13:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.1.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.1.3:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.2.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.2.1:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.2.2:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.2.3:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.2.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.2.5:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.3.4:*:*:*:*:*:*:*

History

20 Nov 2024, 23:59

Type Values Removed Values Added
References () http://developer.berlios.de/project/shownotes.php?release_id=6617 - Patch () http://developer.berlios.de/project/shownotes.php?release_id=6617 - Patch
References () http://fetchmail.berlios.de/fetchmail-SA-2005-01.txt - Patch, Vendor Advisory () http://fetchmail.berlios.de/fetchmail-SA-2005-01.txt - Patch, Vendor Advisory
References () http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html - () http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html -
References () http://secunia.com/advisories/16176 - Vendor Advisory () http://secunia.com/advisories/16176 - Vendor Advisory
References () http://secunia.com/advisories/21253 - Vendor Advisory () http://secunia.com/advisories/21253 - Vendor Advisory
References () http://www.debian.org/security/2005/dsa-774 - () http://www.debian.org/security/2005/dsa-774 -
References () http://www.novell.com/linux/security/advisories/2005_18_sr.html - () http://www.novell.com/linux/security/advisories/2005_18_sr.html -
References () http://www.osvdb.org/18174 - () http://www.osvdb.org/18174 -
References () http://www.redhat.com/archives/fedora-announce-list/2005-July/msg00088.html - () http://www.redhat.com/archives/fedora-announce-list/2005-July/msg00088.html -
References () http://www.redhat.com/archives/fedora-announce-list/2005-July/msg00089.html - Patch () http://www.redhat.com/archives/fedora-announce-list/2005-July/msg00089.html - Patch
References () http://www.redhat.com/archives/fedora-announce-list/2005-July/msg00104.html - () http://www.redhat.com/archives/fedora-announce-list/2005-July/msg00104.html -
References () http://www.redhat.com/support/errata/RHSA-2005-640.html - () http://www.redhat.com/support/errata/RHSA-2005-640.html -
References () http://www.securityfocus.com/archive/1/435197/100/0/threaded - () http://www.securityfocus.com/archive/1/435197/100/0/threaded -
References () http://www.securityfocus.com/archive/1/441856/100/200/threaded - () http://www.securityfocus.com/archive/1/441856/100/200/threaded -
References () http://www.securityfocus.com/bid/14349 - Patch () http://www.securityfocus.com/bid/14349 - Patch
References () http://www.securityfocus.com/bid/19289 - () http://www.securityfocus.com/bid/19289 -
References () http://www.us-cert.gov/cas/techalerts/TA06-214A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA06-214A.html - US Government Resource
References () http://www.vupen.com/english/advisories/2005/1171 - () http://www.vupen.com/english/advisories/2005/1171 -
References () http://www.vupen.com/english/advisories/2006/3101 - () http://www.vupen.com/english/advisories/2006/3101 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1038 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1038 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1124 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1124 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8833 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8833 -

Information

Published : 2005-07-27 04:00

Updated : 2024-11-20 23:59


NVD link : CVE-2005-2335

Mitre link : CVE-2005-2335

CVE.ORG link : CVE-2005-2335


JSON object : View

Products Affected

fetchmail

  • fetchmail
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer