Vulnerability Name:

CVE-2006-5974 (CCN-31414)

Assigned:2006-12-31
Published:2006-12-31
Updated:2018-10-17
Summary:fetchmail 6.3.5 and 6.3.6 before 6.3.6-rc4, when refusing a message delivered via the mda option, allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger a NULL pointer dereference when calling the (1) ferror or (2) fflush functions.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-20
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2006-5974

Source: FEDORA
Type: UNKNOWN
FEDORA-2007-041

Source: CCN
Type: fetchmail-SA-2006-03
crash when refusing message delivered through MDA

Source: CONFIRM
Type: UNKNOWN
http://fetchmail.berlios.de/fetchmail-SA-2006-03.txt

Source: OSVDB
Type: UNKNOWN
31836

Source: CCN
Type: SA23631
Fetchmail TLS Configuration Security Issue and "MDA" Denial of Service

Source: SECUNIA
Type: Vendor Advisory
23631

Source: SECUNIA
Type: Vendor Advisory
23804

Source: SECUNIA
Type: Vendor Advisory
23838

Source: SECUNIA
Type: Vendor Advisory
23923

Source: SECUNIA
Type: Vendor Advisory
24151

Source: GENTOO
Type: UNKNOWN
GLSA-200701-13

Source: CCN
Type: SECTRACK ID: 1017479
Fetchmail MDA Option Message Refusal Bugs Let Remote Users Deny Service

Source: SECTRACK
Type: UNKNOWN
1017479

Source: SLACKWARE
Type: UNKNOWN
SSA:2007-024-01

Source: CCN
Type: GLSA-200701-13
Fetchmail: Denial of Service and password disclosure

Source: SUSE
Type: UNKNOWN
SUSE-SR:2007:004

Source: CCN
Type: OpenPKG-SA-2007.004
Fetchmail

Source: OPENPKG
Type: UNKNOWN
OpenPKG-SA-2007.004

Source: CCN
Type: OSVDB ID: 31836
Fetchmail mda Message Refusal DoS

Source: BUGTRAQ
Type: UNKNOWN
20070105 fetchmail security announcement 2006-03 (CVE-2006-5974)

Source: BID
Type: Patch
21902

Source: CCN
Type: BID-21902
Fetchmail Remote Denial of Service Vulnerability

Source: TRUSTIX
Type: UNKNOWN
2007-0007

Source: VUPEN
Type: UNKNOWN
ADV-2007-0087

Source: VUPEN
Type: UNKNOWN
ADV-2007-0088

Source: XF
Type: UNKNOWN
fetchmail-mda-dos(31414)

Source: SUSE
Type: SUSE-SA:2007:008
XFree86/Xorg security problems

Source: SUSE
Type: SUSE-SR:2007:001
SUSE Security Summary Report

Source: SUSE
Type: SUSE-SR:2007:003
SUSE Security Summary Report

Source: SUSE
Type: SUSE-SR:2007:004
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/a:fetchmail:fetchmail:6.3.5:*:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:6.3.6:rc1:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:6.3.6:rc2:*:*:*:*:*:*
  • OR cpe:/a:fetchmail:fetchmail:6.3.6:rc3:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20065974
    V
    CVE-2006-5974
    2022-06-30
    oval:org.opensuse.security:def:112218
    P
    fetchmail-6.4.21-2.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:26220
    P
    Security update for MozillaFirefox (Important) (in QA)
    2022-01-14
    oval:org.opensuse.security:def:31373
    P
    Security update for net-snmp (Important)
    2022-01-05
    oval:org.opensuse.security:def:42301
    P
    Security update for libvirt (Important)
    2022-01-04
    oval:org.opensuse.security:def:26176
    P
    Security update for speex (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:33048
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-11-23
    oval:org.opensuse.security:def:26162
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:105749
    P
    fetchmail-6.4.21-2.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:26123
    P
    Security update for openssl-1_0_0 (Low)
    2021-09-09
    oval:org.opensuse.security:def:32181
    P
    Security update for xen (Important)
    2021-09-06
    oval:org.opensuse.security:def:31676
    P
    Security update for openexr (Important)
    2021-09-02
    oval:org.opensuse.security:def:31678
    P
    Security update for file (Important)
    2021-09-02
    oval:org.opensuse.security:def:31671
    P
    Security update for openssl (Important)
    2021-08-24
    oval:org.opensuse.security:def:31249
    P
    Security update for python-PyYAML (Important)
    2021-08-24
    oval:org.opensuse.security:def:26099
    P
    Security update for libsndfile (Critical)
    2021-08-05
    oval:org.opensuse.security:def:31230
    P
    Security update for linuxptp (Important)
    2021-07-21
    oval:org.opensuse.security:def:42102
    P
    Security update for the Linux Kernel (Important)
    2021-07-14
    oval:org.opensuse.security:def:32137
    P
    Security update for libsolv (Important)
    2021-06-28
    oval:org.opensuse.security:def:26074
    P
    Security update for freeradius-server (Moderate)
    2021-06-11
    oval:org.opensuse.security:def:36124
    P
    fetchmail-6.3.8.90-13.20.19.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:32115
    P
    Security update for spice (Important)
    2021-06-08
    oval:org.opensuse.security:def:42531
    P
    fetchmail-6.3.8.90-13.20.19.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:31622
    P
    Security update for graphviz (Critical)
    2021-05-19
    oval:org.opensuse.security:def:31175
    P
    Security update for graphviz (Critical)
    2021-05-19
    oval:org.opensuse.security:def:31617
    P
    Security update for samba (Important)
    2021-05-04
    oval:org.opensuse.security:def:31164
    P
    Security update for libnettle (Important)
    2021-04-28
    oval:org.opensuse.security:def:32076
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP3) (Important)
    2021-04-28
    oval:org.opensuse.security:def:31163
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
    2021-04-28
    oval:org.opensuse.security:def:31361
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2021-03-17
    oval:org.opensuse.security:def:31362
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP3) (Important)
    2021-03-17
    oval:org.opensuse.security:def:33087
    P
    Security update for java-1_8_0-ibm (Important)
    2021-02-26
    oval:org.opensuse.security:def:31728
    P
    Security update for jasper (Important)
    2021-02-16
    oval:org.opensuse.security:def:32256
    P
    Security update for wpa_supplicant (Important)
    2021-02-15
    oval:org.opensuse.security:def:31727
    P
    Security update for wpa_supplicant (Important)
    2021-02-15
    oval:org.opensuse.security:def:31322
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
    2021-02-10
    oval:org.opensuse.security:def:32200
    P
    Security update for python3 (Important)
    2021-02-08
    oval:org.opensuse.security:def:31098
    P
    Security update for MozillaFirefox (Critical)
    2020-12-21
    oval:org.opensuse.security:def:35894
    P
    fetchmail-6.3.8.90-13.20.19.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35544
    P
    fetchmail-6.3.8.90-13.16.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:41951
    P
    fetchmail-6.3.8.90-13.16.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35695
    P
    fetchmail-6.3.8.90-13.20.19.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:32819
    P
    Security update for python-setuptools (Important)
    2020-12-02
    oval:org.opensuse.security:def:31024
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:31379
    P
    Security update for openssl1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31878
    P
    Security update for dhcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32621
    P
    zoo on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31473
    P
    Security update for procmail
    2020-12-01
    oval:org.opensuse.security:def:32027
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31579
    P
    Security update for supportutils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32366
    P
    Security update for supportutils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32044
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25827
    P
    Security update for flash-player (Critical)
    2020-12-01
    oval:org.opensuse.security:def:25171
    P
    Security update for mailman (Important)
    2020-12-01
    oval:org.opensuse.security:def:25521
    P
    Security update for libexif (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25964
    P
    Security update for libraw (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26695
    P
    fetchmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25258
    P
    Security update for postgresql10 (Low)
    2020-12-01
    oval:org.opensuse.security:def:25588
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:26858
    P
    aaa_base on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25445
    P
    Security update for accountsservice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25729
    P
    Security update for spamassassin (Important)
    2020-12-01
    oval:org.opensuse.security:def:26303
    P
    Security update for dnsmasq (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26449
    P
    Security update for nginx (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25673
    P
    Security update for openldap2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25877
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:31788
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:31466
    P
    Security update for postgresql94 (Important)
    2020-12-01
    oval:org.opensuse.security:def:31917
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32660
    P
    fetchmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31530
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:32410
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31590
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31808
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25725
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:25871
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25095
    P
    Security update for mariadb-100 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25299
    P
    Security update for webkit2gtk3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25823
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:25978
    P
    Security update for tcpdump, libpcap (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25322
    P
    Security update for tigervnc (Critical)
    2020-12-01
    oval:org.opensuse.security:def:25672
    P
    Security update for java-1_7_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:26893
    P
    fetchmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25456
    P
    Security update for ghostscript (Important)
    2020-12-01
    oval:org.opensuse.security:def:25786
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26352
    P
    Security update for Mozilla Thunderbird (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27087
    P
    augeas on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25674
    P
    Security update for the Linux Kernel (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25958
    P
    Security update for libwpd (Important)
    2020-12-01
    oval:org.opensuse.security:def:31832
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:31012
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:31773
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:31939
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:32858
    P
    fetchmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32305
    P
    Security update for python (Important)
    2020-12-01
    oval:org.opensuse.security:def:31591
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31900
    P
    Security update for Mozilla Firefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:25774
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26509
    P
    Security update for cacti, cacti-spine (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25096
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25380
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25876
    P
    Security update for libssh (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26022
    P
    Security update for icu (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25246
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25450
    P
    Security update for bluez (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26021
    P
    Security update for libreoffice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25520
    P
    Security update for krb5-appl (Important)
    2020-12-01
    oval:org.opensuse.security:def:25870
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26391
    P
    Security update for MozillaThunderbird (Important)
    2020-12-01
    oval:org.opensuse.security:def:27122
    P
    fetchmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25685
    P
    Security update for mariadb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26015
    P
    Security update for libplist (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32470
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:31013
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:31829
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:31983
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:31381
    P
    Security update for openssl1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:31971
    P
    Security update for jakarta-commons-collections (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31447
    P
    Security update for postgresql94 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31815
    P
    Security update for apache2-mod_perl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32344
    P
    Security update for spice (Important)
    2020-12-01
    oval:org.opensuse.security:def:31602
    P
    Security update for tomcat6
    2020-12-01
    oval:org.opensuse.security:def:31957
    P
    Security update for gdk2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25813
    P
    Security update for libssh (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26544
    P
    fetchmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25107
    P
    Security update for openssl-1_1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25437
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:25925
    P
    Security update for pcre (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26660
    P
    NetworkManager-gnome on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25247
    P
    Security update for libpng16 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25531
    P
    Security update for ucode-intel (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25444
    P
    Security update for sysstat (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25648
    P
    Security update for python36 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26250
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26405
    P
    Security update for sox (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25749
    P
    Security update for pidgin (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31766
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:32509
    P
    fetchmail on GA media (Moderate)
    2020-12-01
    BACK
    fetchmail fetchmail 6.3.5
    fetchmail fetchmail 6.3.6 rc1
    fetchmail fetchmail 6.3.6 rc2
    fetchmail fetchmail 6.3.6 rc3