Vulnerability Description
Fetchmail 6.2.4 and earlier does not properly allocate memory for long lines, which allows remote attackers to cause a denial of service (crash) via a certain email.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fetchmail | Fetchmail | <= 6.2.4 |
Related Weaknesses (CWE)
References
- ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-004.0/CSSA-2004-0
- http://marc.info/?l=bugtraq&m=107731542827401&w=2
- http://security.gentoo.org/glsa/glsa-200403-10.xmlVendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:101
- http://www.securityfocus.com/advisories/5987
- http://www.securityfocus.com/bid/8843PatchVendor Advisory
- http://www.turbolinux.com/security/TLSA-2003-61.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13450
- ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-004.0/CSSA-2004-0
- http://marc.info/?l=bugtraq&m=107731542827401&w=2
- http://security.gentoo.org/glsa/glsa-200403-10.xmlVendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:101
- http://www.securityfocus.com/advisories/5987
- http://www.securityfocus.com/bid/8843PatchVendor Advisory
- http://www.turbolinux.com/security/TLSA-2003-61.txt
FAQ
What is CVE-2003-0792?
CVE-2003-0792 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Fetchmail 6.2.4 and earlier does not properly allocate memory for long lines, which allows remote attackers to cause a denial of service (crash) via a certain email.
How severe is CVE-2003-0792?
CVE-2003-0792 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2003-0792?
Check the references section above for vendor advisories and patch information. Affected products include: Fetchmail Fetchmail.