FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2010-0562

This CVE name corresponds to:

Entered Topic
2010-02-12 fetchmail -- heap overflow on verbose X.509 display

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2010-0562
Phase Assigned(20100208)

Description

The sdump function in sdump.c in fetchmail 6.3.11, 6.3.12, and 6.3.13, when running in verbose mode on platforms for which char is signed, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an SSL X.509 certificate containing non-printable characters with the high bit set, which triggers a heap-based buffer overflow during escaping.

References

Source Reference
CONFIRM http://mknod.org/svn/fetchmail/branches/BRANCH_6-3/fetchmail-SA-2010-01.txt
CONFIRM http://www.fetchmail.info/fetchmail-SA-2010-01.txt
MANDRIVA MDVSA-2010:037
BID 38088
OSVDB 62114
SECTRACK 1023543
SECUNIA 38391
VUPEN ADV-2010-0296