The sdump function in sdump.c in fetchmail 6.3.11, 6.3.12, and 6.3.13, when running in verbose mode on platforms for which char is signed, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an SSL X.509 certificate containing non-printable characters with the high bit set, which triggers a heap-based buffer overflow during escaping.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2010-02-08T21:00:00

Updated: 2024-08-07T00:52:19.355Z

Reserved: 2010-02-08T00:00:00

Link: CVE-2010-0562

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2010-02-08T21:30:00.483

Modified: 2011-04-27T04:00:00.000

Link: CVE-2010-0562

cve-icon Redhat

Severity : Low

Publid Date: 2010-02-04T00:00:00Z

Links: CVE-2010-0562 - Bugzilla