Record summary

CVE-2001-1009 has a selected CVSS score of 10.0; EIP currently links 2 catalogued exploits.

Description

Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory and possibly gain privileges via a negative index number as part of a response to a LIST request.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBFetchmail 5.x - POP3 Reply Signed Integer IndexExploitDB exploitby Salvatore Sanfilippo -antirez-Not analyzed1 file
ExploitDB

PoC details
ExploitDBFetchmail 5.x - IMAP Reply Signed Integer IndexExploitDB exploitby Sanfillipo antirezNot analyzed1 file
ExploitDB

PoC details

References

11