FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-0321

This CVE name corresponds to:

Entered Topic
2006-01-23 fetchmail -- crash when bouncing a message

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-0321
Phase Assigned(20060119)

Description

fetchmail 6.3.0 and other versions before 6.3.2 allows remote attackers to cause a denial of service (crash) via crafted e-mail messages that cause a free of an invalid pointer when fetchmail bounces the message to the originator or local postmaster.

References

Source Reference
BUGTRAQ 20060122 fetchmail security announcement fetchmail-SA-2006-01 (CVE-2006-0321)
VULNWATCH 20060123 fetchmail security announcement fetchmail-SA-2006-01 (CVE-2006-0321)
CONFIRM http://fetchmail.berlios.de/fetchmail-SA-2006-01.txt
CONFIRM http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=348747
CONFIRM http://developer.berlios.de/project/shownotes.php?release_id=8784
APPLE APPLE-SA-2006-08-01
SLACKWARE SSA:2006-045-01
CERT TA06-214A
BID 16365
BID 19289
VUPEN ADV-2006-0300
VUPEN ADV-2006-3101
OSVDB 22691
SECTRACK 1015527
SECUNIA 18571
SECUNIA 18895
SECUNIA 21253
XF fetchmail-message-bounce-dos(24265)