CVE detail
CVE-2011-1947 — CVE-2011-1947
Published 2011-06-02 · Modified 2026-06-16 · Vendor fetchmail · Product fetchmail · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0255
EPSS probability
exploitation probability, 30d
84.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
fetchmail 5.9.9 through 6.3.19 does not properly limit the wait time after issuing a (1) STARTTLS or (2) STLS request, which allows remote servers to cause a denial of service (application hang) by acknowledging the request but not sending additional packets.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References