Fetchmail STARTTLS Remote Denial of Service Vulnerability
BID:48043
Info
Fetchmail STARTTLS Remote Denial of Service Vulnerability
| Bugtraq ID: | 48043 |
| Class: | Design Error |
| CVE: |
CVE-2011-1947 |
| Remote: | Yes |
| Local: | No |
| Published: | May 30 2011 12:00AM |
| Updated: | Apr 13 2015 09:53PM |
| Credit: | This issue has been reported by vendor. |
| Vulnerable: |
Slackware Linux 10.2 Slackware Linux 10.1 Slackware Linux 10.0 Slackware Linux 9.1 Slackware Linux 9.0 Slackware Linux 8.1 Slackware Linux 13.37 x86_64 Slackware Linux 13.37 Slackware Linux 13.1 x86_64 Slackware Linux 13.1 Slackware Linux 13.0 x86_64 Slackware Linux 13.0 Slackware Linux 12.2 Slackware Linux 12.1 Slackware Linux 12.0 Slackware Linux 11.0 Eric Raymond Fetchmail 6.3.17 Eric Raymond Fetchmail 6.3.16 Eric Raymond Fetchmail 6.3.13 Eric Raymond Fetchmail 6.3.12 Eric Raymond Fetchmail 6.3.11 Eric Raymond Fetchmail 6.3.10 Eric Raymond Fetchmail 6.3.9 Eric Raymond Fetchmail 6.3.8 Eric Raymond Fetchmail 6.3.7 Eric Raymond Fetchmail 6.3.6 Eric Raymond Fetchmail 6.3.5 Eric Raymond Fetchmail 6.3.4 Eric Raymond Fetchmail 6.3.3 Eric Raymond Fetchmail 6.3.2 rc4 Eric Raymond Fetchmail 6.3.2 rc3 Eric Raymond Fetchmail 6.3.2 rc2 Eric Raymond Fetchmail 6.3.2 Eric Raymond Fetchmail 6.3.1 -rc1 Eric Raymond Fetchmail 6.3.1 Eric Raymond Fetchmail 6.3 .0 Eric Raymond Fetchmail 6.3 Eric Raymond Fetchmail 6.2.9 -rc6 Eric Raymond Fetchmail 6.2.6 -pre7 Eric Raymond Fetchmail 6.2.5 .5 Eric Raymond Fetchmail 6.2.5 .4 Eric Raymond Fetchmail 6.2.5 .2 Eric Raymond Fetchmail 6.2.5 .1 Eric Raymond Fetchmail 6.2.5 Eric Raymond Fetchmail 6.2.4 Eric Raymond Fetchmail 6.2.2 Eric Raymond Fetchmail 6.2 .0 Eric Raymond Fetchmail 6.1.3 Eric Raymond Fetchmail 6.1 .0 Eric Raymond Fetchmail 6.0 .0 Eric Raymond Fetchmail 5.9.9 Eric Raymond Fetchmail 6.3.6-rc4 Eric Raymond Fetchmail 6.3.6-rc3 Eric Raymond Fetchmail 6.3.6-rc2 Eric Raymond Fetchmail 6.3.6-rc1 Eric Raymond Fetchmail 6.3.2 rc1 Eric Raymond Fetchmail 6.3.19 Eric Raymond Fetchmail 6.3.18 |
| Not Vulnerable: |
Eric Raymond Fetchmail 6.3.20 |
Discussion
Fetchmail STARTTLS Remote Denial of Service Vulnerability
Fetchmail is prone to a denial-of-service vulnerability because the application fails to properly handle SSL/TLS negotiation.
An attacker can exploit this issue to cause an application hang, denying service to legitimate users.
Fetchmail version 5.9.9 up to and including 6.3.19 are vulnerable.
Fetchmail is prone to a denial-of-service vulnerability because the application fails to properly handle SSL/TLS negotiation.
An attacker can exploit this issue to cause an application hang, denying service to legitimate users.
Fetchmail version 5.9.9 up to and including 6.3.19 are vulnerable.
Exploit / POC
Fetchmail STARTTLS Remote Denial of Service Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
References
Fetchmail STARTTLS Remote Denial of Service Vulnerability
References:
References: