Vulnerability Name:

CVE-2005-2335 (CCN-21479)

Assigned:2005-07-21
Published:2005-07-21
Updated:2018-10-19
Summary:Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute arbitrary code via long UIDL responses.
Note: a typo in an advisory accidentally used the wrong CVE identifier for the Fetchmail issue. This is the correct identifier.
CVSS v3 Severity:9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.9 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
7.6 High (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C)
6.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-119
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: Full-disclosure Mailing List, Tue Jul 26 2005 - 05:38:32 CDT
[USN-153-1] fetchmail vulnerability

Source: CCN
Type: Full-Disclosure Mailing List, Tue Aug 01 2006 - 16:53:01 CDT
DMA[2006-0801a] - 'Apple OSX fetchmail buffer overflow'

Source: CCN
Type: Fetchmail Web Page
The fetchmail Home Page

Source: MITRE
Type: CNA
CVE-2005-2335

Source: CONFIRM
Type: Patch
http://developer.berlios.de/project/shownotes.php?release_id=6617

Source: CCN
Type: Conectiva Linux Security Announcement CLSA-2005:1005
Fix for fetchmail vulnerability

Source: CCN
Type: Apple Security Update 2006-004
About Security Update 2006-004

Source: CCN
Type: fetchmail-SA-2005-01: security announcement
remote code injection vulnerability in fetchmail

Source: CONFIRM
Type: Patch, Vendor Advisory
http://fetchmail.berlios.de/fetchmail-SA-2005-01.txt

Source: APPLE
Type: UNKNOWN
APPLE-SA-2006-08-01

Source: CCN
Type: RHSA-2005-640
fetchmail security update

Source: CCN
Type: SA16176
Fetchmail UIDL Buffer Overflow Vulnerability

Source: SECUNIA
Type: Vendor Advisory
16176

Source: CCN
Type: SA21253
Mac OS X Security Update Fixes Multiple Vulnerabilities

Source: SECUNIA
Type: Vendor Advisory
21253

Source: DEBIAN
Type: UNKNOWN
DSA-774

Source: DEBIAN
Type: DSA-774
fetchmail -- buffer overflow

Source: CCN
Type: GLSA-200507-21
fetchmail: Buffer Overflow

Source: SUSE
Type: UNKNOWN
SUSE-SR:2005:018

Source: CCN
Type: OpenPKG-SA-2005.016
fetchmail

Source: OSVDB
Type: UNKNOWN
18174

Source: CCN
Type: OSVDB ID: 18174
Fetchmail UIDL POP3 Server Response Overflow

Source: FEDORA
Type: UNKNOWN
FEDORA-2005-613

Source: FEDORA
Type: Patch
FEDORA-2005-614

Source: MISC
Type: UNKNOWN
http://www.redhat.com/archives/fedora-announce-list/2005-July/msg00104.html

Source: REDHAT
Type: UNKNOWN
RHSA-2005:640

Source: BUGTRAQ
Type: UNKNOWN
20060526 rPSA-2006-0084-1 fetchmail

Source: BUGTRAQ
Type: UNKNOWN
20060801 DMA[2006-0801a] - 'Apple OSX fetchmail buffer overflow'

Source: BID
Type: Patch
14349

Source: CCN
Type: BID-14349
Fetchmail POP3 Client Buffer Overflow Vulnerability

Source: CCN
Type: BID-14384
Fetchmail POP3 Client Remote Denial of Service Vulnerabilities

Source: BID
Type: UNKNOWN
19289

Source: CCN
Type: BID-19289
Apple Mac OS X Multiple Security Vulnerabilities

Source: CCN
Type: TLSA-2005-84
Buffer overlow

Source: CCN
Type: USN-153-1
fetchmail vulnerability

Source: CERT
Type: US Government Resource
TA06-214A

Source: VUPEN
Type: UNKNOWN
ADV-2005-1171

Source: VUPEN
Type: UNKNOWN
ADV-2006-3101

Source: XF
Type: UNKNOWN
fetchmail-uidl-bo(21479)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:1038

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:1124

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:8833

Source: SUSE
Type: SUSE-SR:2005:018
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/a:fetchmail:fetchmail:4.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:4.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:4.5.3:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:4.5.4:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:4.5.5:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:4.5.6:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:4.5.7:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:4.5.8:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:4.6.0:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:4.6.1:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:4.6.2:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:4.6.3:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:4.6.4:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:4.6.5:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:4.6.6:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:4.6.7:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:4.6.8:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:4.6.9:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:4.7.0:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:4.7.1:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:4.7.2:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:4.7.3:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:4.7.4:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:4.7.5:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:4.7.6:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:4.7.7:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.0.5:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.0.6:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.0.7:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.0.8:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.2.4:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.2.7:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.2.8:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.3.3:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.3.8:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.4.3:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.4.4:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.4.5:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.5.3:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.5.5:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.5.6:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.6.0:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.7.0:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.7.2:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.7.4:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.8:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.8.1:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.8.2:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.8.3:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.8.4:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.8.5:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.8.6:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.8.11:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.8.13:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.8.14:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.8.17:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.9.0:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.9.4:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.9.5:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.9.8:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.9.10:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.9.11:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:5.9.13:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:6.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:6.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:6.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:6.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:6.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:6.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:6.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:6.2.4:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:6.2.5:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:*:*:*:*:*:*:*:* (Version <= 6.2.5.1)
  • OR cpe:/a:fetchmail:fetchmail:6.3.4:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20052335
    V
    CVE-2005-2335
    2015-11-16
    oval:org.mitre.oval:def:8833
    V
    Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute arbitrary code via long UIDL responses. NOTE: a typo in an advisory accidentally used the wrong CVE identifier for the Fetchmail issue. This is the correct identifier.
    2013-04-29
    oval:org.mitre.oval:def:1124
    V
    RHE4 Fetchmail Buffer Overflow via Long UIDL Responses
    2013-04-08
    oval:org.mitre.oval:def:1038
    V
    RHE3 Fetchmail Buffer Overflow via Long UIDL Responses
    2005-10-12
    oval:org.debian:def:774
    V
    buffer overflow
    2005-08-12
    oval:com.redhat.rhsa:def:20050640
    P
    RHSA-2005:640: fetchmail security update (Important)
    2005-07-25
    BACK
    fetchmail fetchmail 4.5.1
    fetchmail fetchmail 4.5.2
    fetchmail fetchmail 4.5.3
    fetchmail fetchmail 4.5.4
    fetchmail fetchmail 4.5.5
    fetchmail fetchmail 4.5.6
    fetchmail fetchmail 4.5.7
    fetchmail fetchmail 4.5.8
    fetchmail fetchmail 4.6.0
    fetchmail fetchmail 4.6.1
    fetchmail fetchmail 4.6.2
    fetchmail fetchmail 4.6.3
    fetchmail fetchmail 4.6.4
    fetchmail fetchmail 4.6.5
    fetchmail fetchmail 4.6.6
    fetchmail fetchmail 4.6.7
    fetchmail fetchmail 4.6.8
    fetchmail fetchmail 4.6.9
    fetchmail fetchmail 4.7.0
    fetchmail fetchmail 4.7.1
    fetchmail fetchmail 4.7.2
    fetchmail fetchmail 4.7.3
    fetchmail fetchmail 4.7.4
    fetchmail fetchmail 4.7.5
    fetchmail fetchmail 4.7.6
    fetchmail fetchmail 4.7.7
    fetchmail fetchmail 5.0.0
    fetchmail fetchmail 5.0.1
    fetchmail fetchmail 5.0.2
    fetchmail fetchmail 5.0.3
    fetchmail fetchmail 5.0.4
    fetchmail fetchmail 5.0.5
    fetchmail fetchmail 5.0.6
    fetchmail fetchmail 5.0.7
    fetchmail fetchmail 5.0.8
    fetchmail fetchmail 5.1.0
    fetchmail fetchmail 5.1.4
    fetchmail fetchmail 5.2.0
    fetchmail fetchmail 5.2.1
    fetchmail fetchmail 5.2.3
    fetchmail fetchmail 5.2.4
    fetchmail fetchmail 5.2.7
    fetchmail fetchmail 5.2.8
    fetchmail fetchmail 5.3.0
    fetchmail fetchmail 5.3.1
    fetchmail fetchmail 5.3.3
    fetchmail fetchmail 5.3.8
    fetchmail fetchmail 5.4.0
    fetchmail fetchmail 5.4.3
    fetchmail fetchmail 5.4.4
    fetchmail fetchmail 5.4.5
    fetchmail fetchmail 5.5.0
    fetchmail fetchmail 5.5.2
    fetchmail fetchmail 5.5.3
    fetchmail fetchmail 5.5.5
    fetchmail fetchmail 5.5.6
    fetchmail fetchmail 5.6.0
    fetchmail fetchmail 5.7.0
    fetchmail fetchmail 5.7.2
    fetchmail fetchmail 5.7.4
    fetchmail fetchmail 5.8
    fetchmail fetchmail 5.8.1
    fetchmail fetchmail 5.8.2
    fetchmail fetchmail 5.8.3
    fetchmail fetchmail 5.8.4
    fetchmail fetchmail 5.8.5
    fetchmail fetchmail 5.8.6
    fetchmail fetchmail 5.8.11
    fetchmail fetchmail 5.8.13
    fetchmail fetchmail 5.8.14
    fetchmail fetchmail 5.8.17
    fetchmail fetchmail 5.9.0
    fetchmail fetchmail 5.9.4
    fetchmail fetchmail 5.9.5
    fetchmail fetchmail 5.9.8
    fetchmail fetchmail 5.9.10
    fetchmail fetchmail 5.9.11
    fetchmail fetchmail 5.9.13
    fetchmail fetchmail 6.0.0
    fetchmail fetchmail 6.1.0
    fetchmail fetchmail 6.1.3
    fetchmail fetchmail 6.2.0
    fetchmail fetchmail 6.2.1
    fetchmail fetchmail 6.2.2
    fetchmail fetchmail 6.2.3
    fetchmail fetchmail 6.2.4
    fetchmail fetchmail 6.2.5
    fetchmail fetchmail *
    fetchmail fetchmail 6.3.4