CVE-2002-1175: Input Validation
The getmxrecord function in Fetchmail 6.0.0 and earlier does not properly check the boundary of a particular malformed DNS packet from a malicious DNS server, which allows remote attackers to cause a denial of service (crash) when Fetchmail attempts to read data beyond the expected boundary.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1175?
The severity of CVE-2002-1175 is classified as a denial of service vulnerability.
Is my version of Fetchmail affected by CVE-2002-1175?
Fetchmail versions 6.0.0 and earlier, including various earlier versions, are affected by CVE-2002-1175.
How do I mitigate CVE-2002-1175?
To mitigate CVE-2002-1175, update Fetchmail to version 6.0.1 or later.
What issue does CVE-2002-1175 cause?
CVE-2002-1175 allows remote attackers to cause a denial of service condition by exploiting a malformed DNS packet.
What is the potential impact of CVE-2002-1175 on my system?
The potential impact of CVE-2002-1175 is that it may crash the Fetchmail service due to improper handling of DNS packets.