V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2012-3482
DEB
Medium

Fetchmail 5.0.8 through 6.3.21, when using NTLM authentication in debug mode, allows remote NTLM servers to (1) cause a denial of service (…

CVSS
5.0
Medium
EPSS
0.02
p76
Published
2012-01-01
Updated
2012-01-01
Description

Fetchmail 5.0.8 through 6.3.21, when using NTLM authentication in debug mode, allows remote NTLM servers to (1) cause a denial of service (crash and delayed delivery of inbound mail) via a crafted NTLM response that triggers an out-of-bounds read in the base64 decoder, or (2) obtain sensitive information from memory via an NTLM Type 2 message with a crafted Target Name structure, which triggers an out-of-bounds read.

Affected products
FetchmailFetchmailFetchmailFetchmailFetchmailFetchmailFetchmailFetchmailFetchmailFetchmailFetchmailFetchmailFetchmailFetchmailFetchmailFetchmailFetchmailFetchmailFetchmailFetchmail
CVSS vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Timeline
2012-01-01
Published
2012-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.019 · p76
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
fetchmailTracked
fetchmailTracked
fetchmailTracked
fetchmailTracked
fetchmailTracked
fetchmailTracked
fetchmailTracked
fetchmailTracked
fetchmailTracked
fetchmailTracked
fetchmailTracked
fetchmailTracked
fetchmailTracked
fetchmailTracked
fetchmailTracked
fetchmailTracked
fetchmailTracked
fetchmailTracked
fetchmailTracked
fetchmailTracked
Showing first 20 of 22
Source databases
DEB
CVE
UBU