>> Fetchmail Multiple Password Disclosure and Remote Denial of Service Vulnerabilities
Title : Fetchmail Multiple Password Disclosure and Remote Denial of Service Vulnerabilities VUPEN ID : VUPEN/ADV-2007-0087 CVE ID : CVE-2006-5867 - CVE-2006-5974
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-01-09
Technical Description
Multiple vulnerabilities have been identified in Fetchmail, which could be exploited by attackers to bypass security restrictions or cause a denial of service.
The first issue is due to a NULL pointer dereference error when rejecting a message sent to an MDA, which could be exploited by attackers to cause a denial of service.
The second issue is due to various errors where where logins are used omitting the necessary protection through SSL/TLS, which could be exploited by attackers to potentially gain knowledge of sensitive information.