Loading vulnerability details…
CVSS v3.1
N/A
EPSS
1.99%
Published
Oct 11, 2002
Modified
Jun 16, 2026
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The getmxrecord function in Fetchmail 6.0.0 and earlier does not properly check the boundary of a particular malformed DNS packet from a malicious DNS server, which allows remote attackers to cause a denial of service (crash) when Fetchmail attempts to read data beyond the expected boundary.
Weaknesses (CWE)
Affected Products (79)
References (16)
...and 29 more