CVE-2010-0562

EUVD-2010-0593
The sdump function in sdump.c in fetchmail 6.3.11, 6.3.12, and 6.3.13, when running in verbose mode on platforms for which char is signed, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an SSL X.509 certificate containing non-printable characters with the high bit set, which triggers a heap-based buffer overflow during escaping.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
Affected Products (NVD)
VendorProductVersion
fetchmailfetchmail
6.3.11
fetchmailfetchmail
6.3.12
fetchmailfetchmail
6.3.13
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
fetchmail
bookworm
6.4.37-1
fixed
bullseye
6.4.16-4+deb11u1
fixed
etch
not-affected
lenny
not-affected
sid
6.4.39-1
fixed
trixie
6.4.39-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
fetchmail
dapper
not-affected
hardy
not-affected
intrepid
not-affected
jaunty
not-affected
karmic
not-affected