CVE-2012-3482: Medium severity Fetchmail Fetchmail vulnerability
Fetchmail 5.0.8 through 6.3.21, when using NTLM authentication in debug mode, allows remote NTLM servers to (1) cause a denial of service (crash and delayed delivery of inbound mail) via a crafted NTLM response that triggers an out-of-bounds read in the base64 decoder, or (2) obtain sensitive information from memory via an NTLM Type 2 message with a crafted Target Name structure, which triggers an out-of-bounds read.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3482?
CVE-2012-3482 has a moderate severity rating due to its potential for denial of service and compromising sensitive information.
How do I fix CVE-2012-3482?
To fix CVE-2012-3482, upgrade Fetchmail to version 6.3.22 or later, where the vulnerability is patched.
What does CVE-2012-3482 affect?
CVE-2012-3482 affects multiple versions of Fetchmail from 5.0.8 through 6.3.21 when using NTLM authentication.
Is there a workaround for CVE-2012-3482?
A temporary workaround for CVE-2012-3482 is to disable NTLM authentication until an upgrade can be performed.
What are the potential impacts of CVE-2012-3482?
The potential impacts of CVE-2012-3482 include denial of service and the risk of sensitive information being exposed.