CVE-2006-5974: Input Validation
Published Dec 31, 2006
·Updated
fetchmail 6.3.5 and 6.3.6 before 6.3.6-rc4, when refusing a message delivered via the mda option, allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger a NULL pointer dereference when calling the (1) ferror or (2) fflush functions.
Affected Software
4 affected components
Fetchmail Fetchmail=6.3.5
Fetchmail Fetchmail=6.3.6-rc2
Fetchmail Fetchmail=6.3.6-rc3
Fetchmail Fetchmail=6.3.6-rc1
Remediation
Patch Available
Event History
Dec 31, 2006
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 9, 2007
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-5974?
CVE-2006-5974 has a medium severity rating due to its potential to cause denial of service.
2
How do I fix CVE-2006-5974?
To resolve CVE-2006-5974, upgrade to fetchmail version 6.3.6-rc4 or later.
3
What versions of fetchmail are affected by CVE-2006-5974?
CVE-2006-5974 affects fetchmail versions 6.3.5 and 6.3.6 prior to version 6.3.6-rc4.
4
What impact does CVE-2006-5974 have on my system?
CVE-2006-5974 can cause a crash of the fetchmail application, leading to denial of service.
5
Is CVE-2006-5974 remotely exploitable?
Yes, CVE-2006-5974 can be exploited by remote attackers through specific vectors.