This script is Copyright (C) 2007-2015 Tenable Network Security, Inc.
The remote Gentoo host is missing one or more security-related
The remote host is affected by the vulnerability described in GLSA-200701-13
(Fetchmail: Denial of Service and password disclosure)
Neil Hoggarth has discovered that when delivering messages to a message
delivery agent by means of the 'mda' option, Fetchmail passes a NULL
pointer to the ferror() and fflush() functions when refusing a message.
Isaac Wilcox has discovered numerous means of plain-text password
disclosure due to errors in secure connection establishment.
An attacker could deliver a message via Fetchmail to a message delivery
agent configured to refuse the message, and crash the Fetchmail
process. SMTP and LMTP delivery modes are not affected by this
vulnerability. An attacker could also perform a Man-in-the-Middle
attack, and obtain plain-text authentication credentials of users
connecting to a Fetchmail process.
There is no known workaround at this time.
See also :
All fetchmail users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=net-mail/fetchmail-6.3.6'
Risk factor :
High / CVSS Base Score : 7.8
CVSS Temporal Score : 6.8
Public Exploit Available : true
Family: Gentoo Local Security Checks
Nessus Plugin ID: 24249 (gentoo_GLSA-200701-13.nasl)
Bugtraq ID: 2190221903
CVE ID: CVE-2006-5867CVE-2006-5974
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.