CVE-2005-2335
fetchmail - buffer overflow
EPSS 5.9%
描述
Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute arbitrary code via long UIDL responses. NOTE: a typo in an advisory accidentally used the wrong CVE identifier for the Fetchmail issue. This is the correct identifier.
如何修補 CVE-2005-2335
要修補 CVE-2005-2335,請將受影響套件升級到下列已修補版本。
- Debian/fetchmail—升級至 6.2.5-16 或更新版本
- Debian/fetchmail—升級至 6.2.5-12sarge1 或更新版本
CVE-2005-2335 正在被利用嗎?
中等 — EPSS 為 5.9%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 6.2.5-16
- from 0, < 6.2.5-12sarge1