fetchmail denial of service CVE-2008-2711
Bug #240549 reported by
Emanuele Gentili
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
fetchmail (Suse) |
Fix Released
|
High
|
|||
fetchmail (Ubuntu) |
Fix Released
|
Low
|
Scott Kitterman | ||
Dapper |
Won't Fix
|
Low
|
Unassigned | ||
Feisty |
Won't Fix
|
Low
|
Unassigned | ||
Gutsy |
Won't Fix
|
Low
|
Unassigned | ||
Hardy |
Won't Fix
|
Low
|
Unassigned | ||
Intrepid |
Fix Released
|
Low
|
Scott Kitterman |
Bug Description
fetchmail 6.3.8 and earlier, when running in -v -v mode, allows remote attackers to cause a denial of service (crash and persistent mail failure) via a malformed mail message with long headers, which is not properly handled when using vsnprintf to format log messages.
Related branches
lp://staging/~ari-tczew/ubuntu/hardy/fetchmail/fix-CVE-2008-2711
On hold
for merging
into
lp://staging/ubuntu/hardy-security/fetchmail
- Artur Rona: Pending requested
- Ubuntu branches: Pending requested
-
Diff: 91 lines (+71/-0)3 files modifieddebian/changelog (+10/-0)
debian/patches/07_fix_CVE-2008-2711_DoS.patch (+60/-0)
debian/patches/series (+1/-0)
lp://staging/~ari-tczew/ubuntu/dapper/fetchmail/fix-CVE-2008-2711
Rejected
for merging
into
lp://staging/ubuntu/dapper-security/fetchmail
- Ubuntu Security Sponsors Team: Pending requested
-
Diff: 94 lines (+74/-0)3 files modifieddebian/changelog (+10/-0)
debian/patches/00list (+1/-0)
debian/patches/07_fix_CVE-2008-2711_DoS.dpatch (+63/-0)
CVE References
Changed in fetchmail: | |
assignee: | nobody → emgent |
importance: | Undecided → High |
status: | New → In Progress |
Changed in fetchmail: | |
status: | Unknown → Fix Released |
Changed in fetchmail: | |
status: | Triaged → In Progress |
Changed in fetchmail: | |
status: | In Progress → Fix Committed |
Changed in fetchmail: | |
status: | In Progress → Fix Committed |
tags: | added: patch |
Changed in fetchmail (Ubuntu Dapper): | |
status: | Invalid → Won't Fix |
Changed in fetchmail (Ubuntu Feisty): | |
assignee: | Emanuele Gentili (emgent) → nobody |
Changed in fetchmail (Ubuntu Gutsy): | |
assignee: | Emanuele Gentili (emgent) → nobody |
importance: | Undecided → Low |
Changed in fetchmail (Ubuntu Hardy): | |
assignee: | Emanuele Gentili (emgent) → Artur Rona (ari-tczew) |
status: | Triaged → In Progress |
Changed in fetchmail (Ubuntu Hardy): | |
assignee: | Artur Rona (ari-tczew) → nobody |
status: | In Progress → New |
Changed in fetchmail (Ubuntu Hardy): | |
status: | New → Triaged |
Changed in fetchmail (Ubuntu Dapper): | |
status: | Confirmed → Triaged |
Changed in fetchmail (Suse): | |
importance: | Unknown → High |
To post a comment you must log in.
Trying to link this bug to CVE-2008-2711 (the web UI for that doesn't seem to work).