CVE-2009-2666

socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
References
Link Resource
http://fetchmail.berlios.de/fetchmail-SA-2009-01.txt
http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html
http://marc.info/?l=oss-security&m=124949601207156&w=2
http://osvdb.org/56855
http://secunia.com/advisories/36175 Vendor Advisory
http://secunia.com/advisories/36179 Vendor Advisory
http://secunia.com/advisories/36236 Vendor Advisory
http://support.apple.com/kb/HT3937
http://www.debian.org/security/2009/dsa-1852
http://www.mandriva.com/security/advisories?name=MDVSA-2009:201
http://www.securityfocus.com/archive/1/505530/100/0/threaded
http://www.securityfocus.com/bid/35951
http://www.securitytracker.com/id?1022679
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.543463
http://www.vupen.com/english/advisories/2009/2155 Vendor Advisory
http://www.vupen.com/english/advisories/2009/3184 Vendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11059
http://fetchmail.berlios.de/fetchmail-SA-2009-01.txt
http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html
http://marc.info/?l=oss-security&m=124949601207156&w=2
http://osvdb.org/56855
http://secunia.com/advisories/36175 Vendor Advisory
http://secunia.com/advisories/36179 Vendor Advisory
http://secunia.com/advisories/36236 Vendor Advisory
http://support.apple.com/kb/HT3937
http://www.debian.org/security/2009/dsa-1852
http://www.mandriva.com/security/advisories?name=MDVSA-2009:201
http://www.securityfocus.com/archive/1/505530/100/0/threaded
http://www.securityfocus.com/bid/35951
http://www.securitytracker.com/id?1022679
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.543463
http://www.vupen.com/english/advisories/2009/2155 Vendor Advisory
http://www.vupen.com/english/advisories/2009/3184 Vendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11059
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fetchmail:fetchmail:*:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.5.1:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.5.2:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.5.3:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.5.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.5.5:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.5.6:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.5.7:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.5.8:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.1:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.2:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.3:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.5:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.6:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.7:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.8:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.6.9:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.7.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.7.1:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.7.2:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.7.3:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.7.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.7.5:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.7.6:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:4.7.7:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.0.2:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.0.3:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.0.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.0.5:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.0.6:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.0.7:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.0.8:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.1.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.1.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.2.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.2.1:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.2.3:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.2.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.2.7:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.2.8:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.3.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.3.1:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.3.3:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.3.8:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.4.3:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.4.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.4.5:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.5.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.5.2:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.5.3:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.5.5:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.5.6:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.6.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.7.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.7.2:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.7.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.8:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.8.1:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.8.2:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.8.3:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.8.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.8.5:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.8.6:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.8.11:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.8.13:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.8.14:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.8.17:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.9.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.9.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.9.5:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.9.8:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.9.10:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.9.11:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:5.9.13:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.1.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.1.3:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.2.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.2.1:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.2.2:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.2.3:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.2.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.2.5:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.2.5.2:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.2.5.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.2.6:pre4:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.2.6:pre8:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.2.6:pre9:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.2.9:rc10:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.2.9:rc3:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.2.9:rc4:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.2.9:rc5:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.2.9:rc7:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.2.9:rc8:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.2.9:rc9:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.3.0:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.3.1:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.3.2:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.3.3:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.3.4:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.3.5:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.3.6:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.3.6:rc1:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.3.6:rc2:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.3.6:rc3:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.3.6:rc4:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.3.6:rc5:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.3.7:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.3.8:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.3.9:*:*:*:*:*:*:*
cpe:2.3:a:fetchmail:fetchmail:6.3.9:rc2:*:*:*:*:*:*

History

21 Nov 2024, 01:05

Type Values Removed Values Added
References () http://fetchmail.berlios.de/fetchmail-SA-2009-01.txt - () http://fetchmail.berlios.de/fetchmail-SA-2009-01.txt -
References () http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html - () http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html -
References () http://marc.info/?l=oss-security&m=124949601207156&w=2 - () http://marc.info/?l=oss-security&m=124949601207156&w=2 -
References () http://osvdb.org/56855 - () http://osvdb.org/56855 -
References () http://secunia.com/advisories/36175 - Vendor Advisory () http://secunia.com/advisories/36175 - Vendor Advisory
References () http://secunia.com/advisories/36179 - Vendor Advisory () http://secunia.com/advisories/36179 - Vendor Advisory
References () http://secunia.com/advisories/36236 - Vendor Advisory () http://secunia.com/advisories/36236 - Vendor Advisory
References () http://support.apple.com/kb/HT3937 - () http://support.apple.com/kb/HT3937 -
References () http://www.debian.org/security/2009/dsa-1852 - () http://www.debian.org/security/2009/dsa-1852 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2009:201 - () http://www.mandriva.com/security/advisories?name=MDVSA-2009:201 -
References () http://www.securityfocus.com/archive/1/505530/100/0/threaded - () http://www.securityfocus.com/archive/1/505530/100/0/threaded -
References () http://www.securityfocus.com/bid/35951 - () http://www.securityfocus.com/bid/35951 -
References () http://www.securitytracker.com/id?1022679 - () http://www.securitytracker.com/id?1022679 -
References () http://www.slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.543463 - () http://www.slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.543463 -
References () http://www.vupen.com/english/advisories/2009/2155 - Vendor Advisory () http://www.vupen.com/english/advisories/2009/2155 - Vendor Advisory
References () http://www.vupen.com/english/advisories/2009/3184 - Vendor Advisory () http://www.vupen.com/english/advisories/2009/3184 - Vendor Advisory
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11059 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11059 -

Information

Published : 2009-08-07 19:00

Updated : 2024-11-21 01:05


NVD link : CVE-2009-2666

Mitre link : CVE-2009-2666

CVE.ORG link : CVE-2009-2666


JSON object : View

Products Affected

fetchmail

  • fetchmail
CWE
CWE-310

Cryptographic Issues