Secunia Logo
 
CVE Reference: CVE-2005-2335
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-2335

Description:
Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute arbitrary code via long UIDL responses. NOTE: a typo in an advisory accidentally used the wrong CVE identifier for the Fetchmail issue. This is the correct identifier.

CVE Status:
Candidate

References:

SUSE
  http://www.novell.com/linux/security/advisories/2005_18_sr.html

SAID
  Secunia Advisory: SA16176
  Secunia Advisory: SA21253

REDHAT
  http://www.redhat.com/support/errata/RHSA-2005-640.html

OVAL
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1038
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1124

OSVDB
  18174

MISC
  http://www.redhat.com/archives/fedora-announce-list/2005-July/msg00104.html

FEDORA
  http://www.redhat.com/archives/fedora-announce-list/2005-July/msg00089.html
  http://www.redhat.com/archives/fedora-announce-list/2005-July/msg00088.html

DEBIAN
  http://www.debian.org/security/2005/dsa-774

CONFIRM
  http://developer.berlios.de/project/shownotes.php?release_id=6617
  http://fetchmail.berlios.de/fetchmail-SA-2005-01.txt

CERT
  http://www.us-cert.gov/cas/techalerts/TA06-214A.html

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/441856/100/200/threaded
  http://www.securityfocus.com/archive/1/archive/1/435197/100/0/threaded

BID
  14349
  19289

APPLE
  http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html


Return to the previous page.