Vulnerability Name:

CVE-2005-3088 (CCN-22842)

Assigned:2005-10-21
Published:2005-10-21
Updated:2018-10-03
Summary:fetchmailconf before 1.49 in fetchmail 6.2.0, 6.2.5 and 6.2.5.2 creates configuration files with insecure world-readable permissions, which allows local users to obtain sensitive information such as passwords.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
1.8 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
1.8 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-200
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2005-3088

Source: CCN
Type: BerliOS Developer Project Filelist Web site
Project: Community Fetchmail - Files

Source: CCN
Type: Apple Security Update 2006-004
About Security Update 2006-004

Source: CCN
Type: Fetchmail Web Page
The fetchmail Home Page

Source: CCN
Type: fetchmail-SA-2005-02: security announcement
password exposure in fetchmailconf

Source: CONFIRM
Type: Patch, Vendor Advisory
http://fetchmail.berlios.de/fetchmail-SA-2005-02.txt

Source: APPLE
Type: UNKNOWN
APPLE-SA-2006-08-01

Source: BUGTRAQ
Type: UNKNOWN
20051027 fetchmail security announcement 2005-02 (CVE-2005-3088)

Source: CCN
Type: RHSA-2005-823
fetchmail security update

Source: CCN
Type: SA17293
Fetchmail "fetchmailconf" Password Disclosure Vulnerability

Source: SECUNIA
Type: Patch, Vendor Advisory
17293

Source: SECUNIA
Type: Vendor Advisory
17349

Source: SECUNIA
Type: Vendor Advisory
17446

Source: SECUNIA
Type: Vendor Advisory
17491

Source: SECUNIA
Type: Vendor Advisory
17495

Source: SECUNIA
Type: Vendor Advisory
17631

Source: SECUNIA
Type: Vendor Advisory
18895

Source: CCN
Type: SA21253
Mac OS X Security Update Fixes Multiple Vulnerabilities

Source: SECUNIA
Type: Vendor Advisory
21253

Source: CCN
Type: SECTRACK ID: 1015114
Fetchmail `fetchmailconf` May Disclose Passwords to Local Users

Source: SECTRACK
Type: UNKNOWN
1015114

Source: SLACKWARE
Type: UNKNOWN
SSA:2006-045-01

Source: DEBIAN
Type: UNKNOWN
DSA-900

Source: DEBIAN
Type: DSA-900
fetchmail -- programming error

Source: CCN
Type: GLSA-200511-06
fetchmail: Password exposure in fetchmailconf

Source: GENTOO
Type: UNKNOWN
GLSA-200511-06

Source: MANDRIVA
Type: UNKNOWN
MDKSA-2005:209

Source: OSVDB
Type: UNKNOWN
20267

Source: CCN
Type: OSVDB ID: 20267
Fetchmail fetchmailconf Race Condition Password Disclosure

Source: REDHAT
Type: UNKNOWN
RHSA-2005:823

Source: BID
Type: Patch
15179

Source: CCN
Type: BID-15179
Fetchmail's FetchmailConf Utility Local Information Disclosure Vulnerability

Source: BID
Type: UNKNOWN
19289

Source: CCN
Type: BID-19289
Apple Mac OS X Multiple Security Vulnerabilities

Source: CCN
Type: TLSA-2007-3
Three vulnerabilities discovered in fetchmail

Source: CCN
Type: USN-215-1
fetchmail vulnerability

Source: CERT
Type: US Government Resource
TA06-214A

Source: VUPEN
Type: UNKNOWN
ADV-2005-2182

Source: VUPEN
Type: UNKNOWN
ADV-2006-3101

Source: XF
Type: UNKNOWN
fetchmail-information-disclosure(22842)

Source: UBUNTU
Type: UNKNOWN
USN-215-1

Vulnerable Configuration:Configuration 1:
  • cpe:/a:fetchmail:fetchmail:6.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:6.2.5:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:6.2.5.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.debian:def:900
    V
    programming error
    2013-01-21
    BACK
    fetchmail fetchmail 6.2.0
    fetchmail fetchmail 6.2.5
    fetchmail fetchmail 6.2.5.2