MEDIUM
fetchmail: SSL null terminator bypass
Published Aug 7, 2009
6.4
MEDIUMCVSS 2.0
EPSS 1.50%
Description
socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Affected products
No data.
OR
- ≤ 6.3.10
- 4.5.1
- 4.5.2
- 4.5.3
- 4.5.4
- 4.5.5
- 4.5.6
- 4.5.7
- 4.5.8
- 4.6.0
- 4.6.1
- 4.6.2
- 4.6.3
- 4.6.4
- 4.6.5
- 4.6.6
- 4.6.7
- 4.6.8
- 4.6.9
- 4.7.0
- 4.7.1
- 4.7.2
- 4.7.3
- 4.7.4
- 4.7.5
- 4.7.6
- 4.7.7
- 5.0.0
- 5.0.1
- 5.0.2
- 5.0.3
- 5.0.4
- 5.0.5
- 5.0.6
- 5.0.7
- 5.0.8
- 5.1.0
- 5.1.4
- 5.2.0
- 5.2.1
- 5.2.3
- 5.2.4
- 5.2.7
- 5.2.8
- 5.3.0
- 5.3.1
- 5.3.3
- 5.3.8
- 5.4.0
- 5.4.3
- 5.4.4
- 5.4.5
- 5.5.0
- 5.5.2
- 5.5.3
- 5.5.5
- 5.5.6
- 5.6.0
- 5.7.0
- 5.7.2
- 5.7.4
- 5.8
- 5.8.1
- 5.8.2
- 5.8.3
- 5.8.4
- 5.8.5
- 5.8.6
- 5.8.11
- 5.8.13
- 5.8.14
- 5.8.17
- 5.9.0
- 5.9.4
- 5.9.5
- 5.9.8
- 5.9.10
- 5.9.11
- 5.9.13
- 6.0.0
- 6.1.0
- 6.1.3
- 6.2.0
- 6.2.1
- 6.2.2
- 6.2.3
- 6.2.4
- 6.2.5
- 6.2.5.1
- 6.2.5.2
- 6.2.5.4
- 6.2.6
- 6.2.6
- 6.2.6
- 6.2.9
- 6.2.9
- 6.2.9
- 6.2.9
- 6.2.9
- 6.2.9
- 6.2.9
- 6.3.0
- 6.3.1
- 6.3.2
- 6.3.3
- 6.3.4
- 6.3.5
- 6.3.6
- 6.3.6
- 6.3.6
- 6.3.6
- 6.3.6
- 6.3.6
- 6.3.7
- 6.3.8
- 6.3.9
- 6.3.9
No data.
Red Hat Enterprise Linux 3
fetchmail-0:6.2.0-3.el3.5
Fixed · RHSA-2009:1427
Red Hat Enterprise Linux 4
fetchmail-0:6.2.5-6.0.1.el4_8.1
Fixed · RHSA-2009:1427
Red Hat Enterprise Linux 5
fetchmail-0:6.3.6-1.1.el5_3.1
Fixed · RHSA-2009:1427
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | fetchmail-0:6.2.0-3.el3.5 | Fixed | RHSA-2009:1427 |
| Red Hat Enterprise Linux 4 | fetchmail-0:6.2.5-6.0.1.el4_8.1 | Fixed | RHSA-2009:1427 |
| Red Hat Enterprise Linux 5 | fetchmail-0:6.3.6-1.1.el5_3.1 | Fixed | RHSA-2009:1427 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (21)
- http://fetchmail.berlios.de/fetchmail-SA-2009-01.txt x_refsource_CONFIRM
- http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html vendor-advisoryx_refsource_APPLE
- http://marc.info/?l=oss-security&m=124949601207156&w=2 mailing-listx_refsource_MLIST
- http://osvdb.org/56855 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/36175 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/36179 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/36236 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://support.apple.com/kb/HT3937 x_refsource_CONFIRM
- http://www.debian.org/security/2009/dsa-1852 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:201 vendor-advisoryx_refsource_MANDRIVA
- http://www.securityfocus.com/archive/1/505530/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/35951 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1022679 vdb-entryx_refsource_SECTRACK
- http://www.slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.543463 vendor-advisoryx_refsource_SLACKWARE
- http://www.vupen.com/english/advisories/2009/2155 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2009/3184 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2009-2666 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=515804 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2009-2666
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11059 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2009-2666
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 7, 2009
Updated Aug 7, 2024
Reserved Aug 5, 2009
Link CVE-2009-2666
CISA Vulnrichment
Updated n/a