CVE-2005-3088: Infoleak
Published Oct 27, 2005
·Updated
fetchmailconf before 1.49 in fetchmail 6.2.0, 6.2.5 and 6.2.5.2 creates configuration files with insecure world-readable permissions, which allows local users to obtain sensitive information such as passwords.
Affected Software
3 affected components
Fetchmail Fetchmail=6.2.0
Fetchmail Fetchmail=6.2.5
Fetchmail Fetchmail=6.2.5.2
Remediation
Patch Available
Patch Available
Patch Available
Event History
Oct 27, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3088?
CVE-2005-3088 has a medium severity level due to the potential exposure of sensitive information.
2
How do I fix CVE-2005-3088?
To fix CVE-2005-3088, upgrade fetchmail to version 6.2.6 or later, where the issue is resolved.
3
What are the consequences of CVE-2005-3088?
The consequences of CVE-2005-3088 include local users being able to read sensitive configuration files containing passwords.
4
Which versions are affected by CVE-2005-3088?
Versions affected by CVE-2005-3088 include fetchmail 6.2.0, 6.2.5, and 6.2.5.2.
5
Who can exploit CVE-2005-3088?
CVE-2005-3088 can be exploited by local users who have access to the system where the vulnerable versions of fetchmail are installed.