CVE-2002-1174

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
11/10/2002
Last modified:
03/04/2025

Description

Buffer overflows in Fetchmail 6.0.0 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) long headers that are not properly processed by the readheaders function, or (2) via long Received: headers, which are not properly parsed by the parse_received function.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fetchmail:fetchmail:*:*:*:*:*:*:*:* 6.0.0 (including)
cpe:2.3:a:fetchmail:fetchmail:4.5.1:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.5.2:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.5.3:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.5.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.5.5:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.5.6:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.5.7:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.5.8:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.1:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.2:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.3:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.5:*:*:*:*:*:*:*