CVE-2006-5867

Publication date 31 December 2006

Last updated 24 July 2024


Ubuntu priority

fetchmail before 6.3.6-rc4 does not properly enforce TLS and may transmit cleartext passwords over unsecured links if certain circumstances occur, which allows remote attackers to obtain sensitive information via man-in-the-middle (MITM) attacks.

Status

Package Ubuntu Release Status
fetchmail 7.04 feisty
Fixed 6.3.6-1ubuntu2
6.10 edgy
Fixed 6.3.4-1ubuntu4.1
6.06 LTS dapper
Fixed 6.3.2-2ubuntu2.1

References

Related Ubuntu Security Notices (USN)

    • USN-405-1
    • fetchmail vulnerability
    • 11 January 2007

Other references