CVE-2011-1947 REJECTED

fetchmail 5.9.9 through 6.3.19 does not properly limit the wait time after issuing a (1) STARTTLS or (2) STLS request, which allows remote servers to cause a denial of service (application hang) by acknowledging the request but not sending additional packets.

EPSS 2.44% · 85.1th percentile

Risk Scores

EPSS Score
2.44%
85.1th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSfetchmail0
Ubuntu:16.04:LTSfetchmail0

Timeline

References

Open in Interactive Console →