CVE-2011-1947: Medium severity fetchmail vulnerability
fetchmail 5.9.9 through 6.3.19 does not properly limit the wait time after issuing a (1) STARTTLS or (2) STLS request, which allows remote servers to cause a denial of service (application hang) by acknowledging the request but not sending additional packets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1947?
CVE-2011-1947 has been classified as a medium severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2011-1947?
To fix CVE-2011-1947, upgrade Fetchmail to version 6.3.20 or later, where the vulnerability has been addressed.
What does CVE-2011-1947 affect?
CVE-2011-1947 affects multiple versions of Fetchmail, specifically versions from 5.9.9 to 6.3.19.
How does CVE-2011-1947 work?
CVE-2011-1947 allows remote servers to cause application hangs by acknowledging STARTTLS or STLS requests without sending further packets.
Is CVE-2011-1947 exploitable in real-world scenarios?
Yes, CVE-2011-1947 can be exploited in real-world scenarios to disrupt services by triggering application hangs.