FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2007-4565

This CVE name corresponds to:

Entered Topic
2007-09-02 fetchmail -- denial of service on reject of local warning message

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2007-4565
Phase Assigned(20070827)

Description

sink.c in fetchmail before 6.3.9 allows context-dependent attackers to cause a denial of service (NULL dereference and application crash) by refusing certain warning messages that are sent over SMTP.

References

Source Reference
BUGTRAQ 20070907 FLEA-2007-0053-1 fetchmail
BUGTRAQ 20080617 fetchmail security announcement fetchmail-SA-2007-02 (CVE-2007-4565)
CONFIRM http://fetchmail.berlios.de/fetchmail-SA-2007-02.txt
CONFIRM http://mknod.org/svn/fetchmail/branches/BRANCH_6-3/fetchmail-SA-2007-02.txt
CONFIRM https://issues.rpath.com/browse/RPL-1690
CONFIRM http://support.apple.com/kb/HT3438
APPLE APPLE-SA-2009-02-12
DEBIAN DSA-1377
MANDRIVA MDKSA-2007:179
SUSE SUSE-SR:2007:022
TRUSTIX 2007-0028
UBUNTU USN-520-1
BID 25495
OVAL oval:org.mitre.oval:def:10528
VUPEN ADV-2007-3032
VUPEN ADV-2009-0422
OSVDB 45833
SECTRACK 1018627
SECUNIA 27399
SECUNIA 33937
SREASON 3074
XF fetchmail-warning-dos(36385)