Back

HIGH

fetchmail not enforcing TLS for POP3 properly

Published Jan 9, 2007

Description

fetchmail before 6.3.6-rc4 does not properly enforce TLS and may transmit cleartext passwords over unsecured links if certain circumstances occur, which allows remote attackers to obtain sensitive information via man-in-the-middle (MITM) attacks.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (41)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 9, 2007
Updated Aug 7, 2024
Reserved Nov 14, 2006
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Jan 4, 2007