20010809 Fetchmail security advisorymailing list
http://archives.neohapsis.com/archives/bugtraq/2001-08/0118.html CVE-2001-1009
Fetchmail 5.x - POP3 Reply Signed Integer Index
Record summary
CVE-2001-1009 has a selected CVSS score of 10.0; EIP currently links 2 catalogued exploits.
Description
Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory and possibly gain privileges via a negative index number as part of a response to a LIST request.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBFetchmail 5.x - POP3 Reply Signed Integer IndexExploitDB exploitby Salvatore Sanfilippo -antirez-Not analyzed1 file
ExploitDBFetchmail 5.x - IMAP Reply Signed Integer IndexExploitDB exploitby Sanfillipo antirezNot analyzed1 file
References
11CLA-2001:419Vendor advisory
http://distro.conectiva.com.br/atualizacoes?id=a&anuncio=000419 DSA-071Vendor advisory
http://www.debian.org/security/2001/dsa-071 fetchmail-signed-integer-index(6965)vdb entry
http://www.iss.net/security_center/static/6965.php MDKSA-2001:072Vendor advisory
http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-072.php3 ESA-20010816-01Vendor advisory
http://www.linuxsecurity.com/advisories/other_advisory-1555.html SuSE-SA:2001:026Vendor advisory
http://www.novell.com/linux/security/advisories/2001_026_fetchmail_txt.html RHSA-2001:103Vendor advisory
http://www.redhat.com/support/errata/RHSA-2001-103.html 3164vdb entry
http://www.securityfocus.com/bid/3164 3166vdb entry
http://www.securityfocus.com/bid/3166 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-1009