fetchmail-SA-2012-02: DoS possible with NTLM authentication in debug mode
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Gentoo Linux |
Fix Released
|
Low
|
|||
fetchmail (Fedora) |
Confirmed
|
Low
|
|||
fetchmail (Ubuntu) |
Fix Released
|
Low
|
Unassigned | ||
Precise |
Won't Fix
|
Low
|
Unassigned |
Bug Description
fetchmail-
Topics: fetchmail denial of service in NTLM protocol phase
Author: Matthias Andree
Version: draft
Announced: 2012-08-13
Type: crash while reading from bad memory location
Impact: fetchmail segfaults and aborts, stalling inbound mail
Danger: low
Acknowledgment: J. Porter Clark
CVE Name: CVE-2012-3482
URL: http://
Project URL: http://
Affects: - fetchmail releases 5.0.8 up to and including 6.3.21
Not affected: - fetchmail releases compiled with NTLM support disabled
- fetchmail releases 6.3.22 and newer
Corrected in: 2012-08-13 Git, among others, see commit
CVE References
Changed in gentoo: | |
importance: | Unknown → Low |
visibility: | private → public |
Changed in fetchmail (Ubuntu): | |
importance: | Undecided → Low |
status: | New → Triaged |
Changed in gentoo: | |
status: | Unknown → Fix Released |
Changed in fetchmail (Fedora): | |
importance: | Unknown → Low |
status: | Unknown → Confirmed |
From oss-security:
etchmail- SA-2012- 02: DoS possible with NTLM authentication in debug mode
Topics: fetchmail denial of service in NTLM protocol phase
Author: Matthias Andree
Version: draft
Announced: 2012-08-13
Type: crash while reading from bad memory location
Impact: fetchmail segfaults and aborts, stalling inbound mail
Danger: low
Acknowledgment: J. Porter Clark
CVE Name: (TBD) www.fetchmail. info/fetchmail- SA-2012- 02.txt www.fetchmail. info/
URL: http://
Project URL: http://
Affects: - fetchmail releases 5.0.8 up to and including 6.3.21
when compiled with NTLM support enabled
Not affected: - fetchmail releases compiled with NTLM support disabled
- fetchmail releases 6.3.22 and newer
Corrected in: 2012-08-13 Git, among others, see commit
3fbc7cd331602 c76f882d1b507cd 05c1d824ba8b