FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-3088

This CVE name corresponds to:

Entered Topic
2005-10-30 fetchmail -- fetchmailconf local password exposure

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-3088
Phase Assigned(20050928)

Description

fetchmailconf before 1.49 in fetchmail 6.2.0, 6.2.5 and 6.2.5.2 creates configuration files with insecure world-readable permissions, which allows local users to obtain sensitive information such as passwords.

References

Source Reference
BUGTRAQ 20051027 fetchmail security announcement 2005-02 (CVE-2005-3088)
VULNWATCH 20051027 fetchmail security announcement 2005-02 (CVE-2005-3088)
CONFIRM http://fetchmail.berlios.de/fetchmail-SA-2005-02.txt
APPLE APPLE-SA-2006-08-01
DEBIAN DSA-900
GENTOO GLSA-200511-06
MANDRIVA MDKSA-2005:209
REDHAT RHSA-2005:823
SLACKWARE SSA:2006-045-01
UBUNTU USN-215-1
CERT TA06-214A
BID 15179
BID 19289
VUPEN ADV-2005-2182
VUPEN ADV-2006-3101
OSVDB 20267
SECTRACK 1015114
SECUNIA 17293
SECUNIA 17491
SECUNIA 17631
SECUNIA 17349
SECUNIA 17446
SECUNIA 17495
SECUNIA 18895
SECUNIA 21253