CVE-2002-1174 describes buffer overflow vulnerabilities in Fetchmail version 6.0.0 and earlier. These flaws, residing in the readheaders and parse_received functions, can be triggered by remote attackers sending excessively long headers, potentially leading to a denial of service or arbitrary code execution. With a CVSS score of 7.5, this vulnerability is remotely exploitable with low attack complexity, allowing for partial confidentiality, integrity, and availability impact. While there is no evidence of active exploitation, no public exploit code, and it is not listed in CISA's KEV catalog, the vulnerability has garnered significant community discussion with 10 mentions, indicating notable awareness despite its age.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.0.0CPE matchmatch criteria | cpe:2.3:a:fetchmail:fetchmail:*:*:*:*:*:*:*:* | ||
4.5.1CPE matchmatch criteria | cpe:2.3:a:fetchmail:fetchmail:4.5.1:*:*:*:*:*:*:* | ||
4.5.2CPE matchmatch criteria | cpe:2.3:a:fetchmail:fetchmail:4.5.2:*:*:*:*:*:*:* | ||
4.5.3CPE matchmatch criteria | cpe:2.3:a:fetchmail:fetchmail:4.5.3:*:*:*:*:*:*:* | ||
4.5.4CPE matchmatch criteria | cpe:2.3:a:fetchmail:fetchmail:4.5.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.