Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2006-5867

21
FAUCET Score

CVE-2006-5867 describes a vulnerability in fetchmail before version 6.3.6-rc4 where it fails to properly enforce TLS, potentially transmitting cleartext passwords. This allows remote attackers to intercept sensitive information through man-in-the-middle attacks. With a CVSS score of 7.8, it represents a high severity risk due to its network attack vector and low attack complexity, leading to a complete compromise of confidentiality. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
<= 6.3.6CPE matchmatch criteria
cpe:2.3:a:fetchmail:fetchmail:*:rc3:*:*:*:*:*:*
4.5.1CPE matchmatch criteria
cpe:2.3:a:fetchmail:fetchmail:4.5.1:*:*:*:*:*:*:*
4.5.2CPE matchmatch criteria
cpe:2.3:a:fetchmail:fetchmail:4.5.2:*:*:*:*:*:*:*
4.5.3CPE matchmatch criteria
cpe:2.3:a:fetchmail:fetchmail:4.5.3:*:*:*:*:*:*:*
4.5.4CPE matchmatch criteria
cpe:2.3:a:fetchmail:fetchmail:4.5.4:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.8HIGH

AV:N/AC:L/Au:N/C:C/I:N/A:N

Confidentiality Impact
COMPLETE
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
4.25%
Probability of exploitation in next 30 days
EPSS Percentile
90.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0425 is in the 82nd percentile among its peer group of 51,466 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: fetchmail-0:5.9.0-21.7.3.el2.1.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: fetchmail-0:6.2.0-3.el3.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: fetchmail-0:6.2.5-6.el4.5
View patch

Vendor Advisories (1)

redhatCVE-2006-5867Moderate

fetchmail not enforcing TLS for POP3 properly

Jan 4, 2007

References

patches.sgi.com / support/free/security/advisories/20070201-01-P.asc
docs.info.apple.com / article.html
fedoranews.org / cms/node/2429
fetchmail.berlios.de / fetchmail-SA-2006-02.txt
lists.apple.com / archives/Security-announce/2007/Apr/msg00001.html
osvdb.org / 31580
secunia.com / advisories/23631
Vendor Advisory
secunia.com / advisories/23695
Vendor Advisory
secunia.com / advisories/23714
Vendor Advisory
secunia.com / advisories/23781
Vendor Advisory
secunia.com / advisories/23804
Vendor Advisory
secunia.com / advisories/23838
Vendor Advisory
secunia.com / advisories/23923
Vendor Advisory
secunia.com / advisories/24007
Vendor Advisory
secunia.com / advisories/24151
Vendor Advisory
secunia.com / advisories/24174
Vendor Advisory
secunia.com / advisories/24284
Vendor Advisory
secunia.com / advisories/24966
Vendor Advisory
security.gentoo.org / glsa/glsa-200701-13.xml
securitytracker.com / id
issues.rpath.com / browse/RPL-919
slackware.com / security/viewer.php
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10566
debian.org / security/2007/dsa-1259
mandriva.com / security/advisories
novell.com / linux/security/advisories/2007_4_sr.html
openpkg.com / security/advisories/OpenPKG-SA-2007.004.html
redhat.com / support/errata/RHSA-2007-0018.html
securityfocus.com / archive/1/456115/100/0/threaded
securityfocus.com / archive/1/460528/100/0/threaded
securityfocus.com / bid/21903
Patch
trustix.org / errata/2007/0007
ubuntu.com / usn/usn-405-1
us-cert.gov / cas/techalerts/TA07-109A.html
US Government Resource
vupen.com / english/advisories/2007/0087
vupen.com / english/advisories/2007/0088
vupen.com / english/advisories/2007/1470