Description
fetchmailconf before 1.49 in fetchmail 6.2.0, 6.2.5 and 6.2.5.2 creates configuration files with insecure world-readable permissions, which allows local users to obtain sensitive information such as passwords.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-900-1 | New fetchmail packages fix potential information leak |
Debian DSA |
DSA-900-2 | New fetchmail packages fix potential information leak |
Debian DSA |
DSA-900-3 | New fetchmail-ssl packages fix potential information leak |
EUVD |
EUVD-2005-3088 | fetchmailconf before 1.49 in fetchmail 6.2.0, 6.2.5 and 6.2.5.2 creates configuration files with insecure world-readable permissions, which allows local users to obtain sensitive information such as passwords. |
Ubuntu USN |
USN-215-1 | fetchmailconf vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T23:01:57.815Z
Reserved: 2005-09-28T00:00:00.000Z
Link: CVE-2005-3088
No data.
Status : Modified
Published: 2005-10-27T10:02:00.000
Modified: 2026-06-16T22:16:13.823
Link: CVE-2005-3088
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Debian DSA
EUVD
Ubuntu USN