← Vulnerability feed

Vulnerability record · CVE-2005-4348 · published 21 December 2005

CVE-2005-4348: Fetchmail vulnerability

Fetchmail · Fetchmail

fetchmail before 6.3.1 and before 6.2.5.5, when configured for multidrop mode, allows remote attackers to cause a denial of service (application crash) by sending messages without headers from upstream mail servers.

7.8 CVSS 2.0 High EPSS 3.6% · top 10.8% CWE-399 · CWE-399
7.8CVSS 2.0 base score
3.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
60References
16 Jun 2026Last modified by NVD

Description

fetchmail before 6.3.1 and before 6.2.5.5, when configured for multidrop mode, allows remote attackers to cause a denial of service (application crash) by sending messages without headers from upstream mail servers.

AV:N/AC:L/Au:N/C:N/I:N/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc Broken Link
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=343836 Issue TrackingMailing ListThird Party Advisory
http://fetchmail.berlios.de/fetchmail-SA-2005-03.txt Broken Link
http://secunia.com/advisories/17891 Third Party Advisory
http://secunia.com/advisories/18172 Third Party Advisory
http://secunia.com/advisories/18231 Third Party Advisory
http://secunia.com/advisories/18266 Third Party Advisory
http://secunia.com/advisories/18433 Third Party Advisory
http://secunia.com/advisories/18463 Third Party Advisory
http://secunia.com/advisories/18895 Third Party Advisory
http://secunia.com/advisories/21253 Third Party Advisory
http://secunia.com/advisories/24007 Third Party Advisory
http://secunia.com/advisories/24284 Third Party Advisory
http://securitytracker.com/id?1015383 Third Party AdvisoryVDB Entry
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.443499 Third Party Advisory
http://www.debian.org/security/2005/dsa-939 Third Party Advisory
http://www.novell.com/linux/security/advisories/2007_4_sr.html Broken Link
http://www.osvdb.org/21906 Broken Link
http://www.redhat.com/support/errata/RHSA-2007-0018.html Third Party Advisory
http://www.securityfocus.com/archive/1/420098/100/0/threaded
http://www.securityfocus.com/archive/1/435197/100/0/threaded
http://www.securityfocus.com/bid/15987 Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/19289 Third Party AdvisoryVDB Entry
http://www.trustix.org/errata/2006/0002/ Broken Link
http://www.vupen.com/english/advisories/2005/2996 Permissions RequiredThird Party Advisory
http://www.vupen.com/english/advisories/2006/3101 Permissions RequiredThird Party Advisory
http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2005:236 Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/23713 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9659 Third Party Advisory
https://usn.ubuntu.com/233-1/
ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc Broken Link
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=343836 Issue TrackingMailing ListThird Party Advisory
http://fetchmail.berlios.de/fetchmail-SA-2005-03.txt Broken Link
http://secunia.com/advisories/17891 Third Party Advisory
http://secunia.com/advisories/18172 Third Party Advisory
http://secunia.com/advisories/18231 Third Party Advisory
http://secunia.com/advisories/18266 Third Party Advisory
http://secunia.com/advisories/18433 Third Party Advisory
http://secunia.com/advisories/18463 Third Party Advisory
http://secunia.com/advisories/18895 Third Party Advisory

Track CVE-2005-4348 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2001-1009Fetchmail permissions and access controls vulnerabilityFetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory and possib…EPSS 6.5%10.0CVE-2001-0101Fetchmail vulnerabilityVulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command.EPSS 1.8%7.8CVE-2006-5867Fetchmail improper input validation vulnerabilityfetchmail before 6.3.6-rc4 does not properly enforce TLS and may transmit cleartext passwords over unsecured links if certain circumstances occur, wh…EPSS 4.4%7.8CVE-2006-5974Fetchmail improper input validation vulnerabilityfetchmail 6.3.5 and 6.3.6 before 6.3.6-rc4, when refusing a message delivered via the mda option, allows remote attackers to cause a denial of servic…EPSS 3.9%7.5CVE-2021-36386Fetchmail vulnerabilityreport_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers…EPSS 2.6%7.5CVE-2002-1365Fetchmail memory buffer overflow vulnerabilityHeap-based buffer overflow in Fetchmail 6.1.3 and earlier does not account for the "@" character when determining buffer lengths for local addresses,…EPSS 5.0%7.5CVE-2002-1174Fetchmail memory buffer overflow vulnerabilityBuffer overflows in Fetchmail 6.0.0 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) long he…EPSS 4.7%7.5CVE-2001-0819Fetchmail memory buffer overflow vulnerabilityA buffer overflow in Linux fetchmail before 5.8.6 allows remote attackers to execute arbitrary code via a large 'To:' field in an email header.EPSS 6.4%

Source: NIST National Vulnerability Database (record CVE-2005-4348), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.