fetchmail not enforcing TLS for POP3 properly
Published Jan 9, 2007
7.8
HIGHCVSS 2.0
EPSS 4.39%
Description
fetchmail before 6.3.6-rc4 does not properly enforce TLS and may transmit cleartext passwords over unsecured links if certain circumstances occur, which allows remote attackers to obtain sensitive information via man-in-the-middle (MITM) attacks.
Affected products
No data.
- ≤ 6.3.6
- 4.5.1
- 4.5.2
- 4.5.3
- 4.5.4
- 4.5.5
- 4.5.6
- 4.5.7
- 4.5.8
- 4.6.0
- 4.6.1
- 4.6.2
- 4.6.3
- 4.6.4
- 4.6.5
- 4.6.6
- 4.6.7
- 4.6.8
- 4.6.9
- 4.7.0
- 4.7.1
- 4.7.2
- 4.7.3
- 4.7.4
- 4.7.5
- 4.7.6
- 4.7.7
- 5.0.0
- 5.0.1
- 5.0.2
- 5.0.3
- 5.0.4
- 5.0.5
- 5.0.6
- 5.0.7
- 5.0.8
- 5.1.0
- 5.1.4
- 5.2.0
- 5.2.1
- 5.2.3
- 5.2.4
- 5.2.7
- 5.2.8
- 5.3.0
- 5.3.1
- 5.3.3
- 5.3.8
- 5.4.0
- 5.4.3
- 5.4.4
- 5.4.5
- 5.5.0
- 5.5.2
- 5.5.3
- 5.5.5
- 5.5.6
- 5.6.0
- 5.7.0
- 5.7.2
- 5.7.4
- 5.8
- 5.8.1
- 5.8.2
- 5.8.3
- 5.8.4
- 5.8.5
- 5.8.6
- 5.8.11
- 5.8.13
- 5.8.14
- 5.8.17
- 5.9.0
- 5.9.4
- 5.9.5
- 5.9.8
- 5.9.10
- 5.9.11
- 5.9.13
- 6.0.0
- 6.1.0
- 6.1.3
- 6.2.0
- 6.2.1
- 6.2.2
- 6.2.3
- 6.2.4
- 6.2.5
- 6.2.5.1
- 6.2.5.2
- 6.2.5.4
- 6.2.6
- 6.2.6
- 6.2.6
- 6.2.9
- 6.2.9
- 6.2.9
- 6.2.9
- 6.2.9
- 6.2.9
- 6.2.9
- 6.3.0
- 6.3.1
- 6.3.2
- 6.3.3
- 6.3.4
- 6.3.5
- 6.3.6
- 6.3.6
No data.
Red Hat Enterprise Linux 2.1
fetchmail-0:5.9.0-21.7.3.el2.1.4
Fixed · RHSA-2007:0018
Red Hat Enterprise Linux 3
fetchmail-0:6.2.0-3.el3.3
Fixed · RHSA-2007:0018
Red Hat Enterprise Linux 4
fetchmail-0:6.2.5-6.el4.5
Fixed · RHSA-2007:0018
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 2.1 | fetchmail-0:5.9.0-21.7.3.el2.1.4 | Fixed | RHSA-2007:0018 |
| Red Hat Enterprise Linux 3 | fetchmail-0:6.2.0-3.el3.3 | Fixed | RHSA-2007:0018 |
| Red Hat Enterprise Linux 4 | fetchmail-0:6.2.5-6.el4.5 | Fixed | RHSA-2007:0018 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:C/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 4.39% (0.04390) | 91.01th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.25% (0.04255) | 89.74th | v5 (v2026.06.15) |
| Mar 30, 2025 | 6.45% (0.06446) | 90.14th | v4 (v2025.03.14) |
| Mar 29, 2025 | 10.27% (0.10274) | 88.52th | v4 (v2025.03.14) |
| Mar 17, 2025 | 5.71% (0.05706) | 89.73th | v4 (v2025.03.14) |
| Dec 12, 2024 | 13.14% (0.13143) | 95.77th | v3 (v2023.03.01) |
| Apr 14, 2024 | 13.14% (0.13143) | 95.44th | v3 (v2023.03.01) |
| Mar 6, 2024 | 10.74% (0.10736) | 94.93th | v3 (v2023.03.01) |
| Jan 27, 2024 | 11.55% (0.11549) | 94.76th | v3 (v2023.03.01) |
| Dec 20, 2023 | 5.47% (0.05469) | 92.43th | v3 (v2023.03.01) |
| Nov 12, 2023 | 2.42% (0.02422) | 88.78th | v3 (v2023.03.01) |
| Oct 5, 2023 | 2.04% (0.02041) | 87.66th | v3 (v2023.03.01) |
| Aug 28, 2023 | 0.66% (0.00663) | 77.07th | v3 (v2023.03.01) |
| Jun 12, 2023 | 0.78% (0.00779) | 78.90th | v3 (v2023.03.01) |
| May 5, 2023 | 0.87% (0.00867) | 80.00th | v3 (v2023.03.01) |
| Mar 30, 2023 | 0.83% (0.00825) | 79.41th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.57% (0.00571) | 74.52th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.36% (0.04358) | 88.02th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.36% (0.04358) | 86.83th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.36% (0.04358) | 70.59th | v2 (v2022.01.01) |
References (41)
- ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc vendor-advisoryx_refsource_SGI
- http://docs.info.apple.com/article.html?artnum=305391 x_refsource_CONFIRM
- http://fedoranews.org/cms/node/2429 vendor-advisoryx_refsource_FEDORA
- http://fetchmail.berlios.de/fetchmail-SA-2006-02.txt x_refsource_CONFIRM
- http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html vendor-advisoryx_refsource_APPLE
- http://osvdb.org/31580 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/23631 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23695 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23714 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23781 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23804 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23838 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23923 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/24007 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/24151 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/24174 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/24284 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/24966 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://security.gentoo.org/glsa/glsa-200701-13.xml vendor-advisoryx_refsource_GENTOO
- http://securitytracker.com/id?1017478 vdb-entryx_refsource_SECTRACK
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.517995 vendor-advisoryx_refsource_SLACKWARE
- http://www.debian.org/security/2007/dsa-1259 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:016 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2007_4_sr.html vendor-advisoryx_refsource_SUSE
- http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.004.html vendor-advisoryx_refsource_OPENPKG
- http://www.redhat.com/support/errata/RHSA-2007-0018.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/456115/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/460528/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/21903 vdb-entryx_refsource_BIDPatch
- http://www.trustix.org/errata/2007/0007 vendor-advisoryx_refsource_TRUSTIX
- http://www.ubuntu.com/usn/usn-405-1 vendor-advisoryx_refsource_UBUNTU
- http://www.us-cert.gov/cas/techalerts/TA07-109A.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vupen.com/english/advisories/2007/0087 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/0088 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/1470 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2006-5867 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=221984 Issue Tracking
- https://issues.rpath.com/browse/RPL-919 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2006-5867
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10566 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2006-5867
Change history (0)
No recorded changes yet.