socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Fetchmail | — | Apply OS X security update 2009-006Upgrade macOS to the latest version | Dec 16, 2011 | Aug 7, 2009 |
| Centos_linux | — | Upgrade fetchmail | Dec 1, 2016 | Aug 7, 2009 |
| Debian | — | Upgrade fetchmail | Jul 30, 2024 | Aug 7, 2009 |
| Freebsd | — | Upgrade fetchmail | Dec 10, 2025 | Aug 11, 2009 |
| Gentoo Linux | — | Upgrade net-mail/fetchmail. | Oct 30, 2017 | Aug 7, 2009 |
| Oracle_linux | — | Upgrade fetchmail | Oct 16, 2024 | Aug 7, 2009 |
| Suse | — | Upgrade fetchmailUpgrade fetchmailconf | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade fetchmail | Nov 8, 2024 | Aug 7, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub