{"id":"UBUNTU-CVE-2011-1947","details":"fetchmail 5.9.9 through 6.3.19 does not properly limit the wait time after issuing a (1) STARTTLS or (2) STLS request, which allows remote servers to cause a denial of service (application hang) by acknowledging the request but not sending additional packets.","modified":"2025-07-16T07:30:46.567221Z","published":"2011-06-02T19:55:00Z","withdrawn":"2025-07-18T16:42:42Z","upstream":["CVE-2011-1947"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2011-1947"},{"type":"REPORT","url":"http://www.fetchmail.info/fetchmail-SA-2011-01.txt"},{"type":"REPORT","url":"http://gitorious.org/fetchmail/fetchmail/blobs/legacy_63/fetchmail-SA-2011-01.txt"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2011-1947"}],"affected":[{"package":{"name":"fetchmail","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/fetchmail@6.3.26-1?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.3.26-1"}]}],"ecosystem_specific":{"binaries":[{"binary_name":"fetchmail","binary_version":"6.3.26-1"},{"binary_name":"fetchmailconf","binary_version":"6.3.26-1"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2011/UBUNTU-CVE-2011-1947.json"}},{"package":{"name":"fetchmail","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/fetchmail@6.3.26-1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.3.26-1"}]}],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"fetchmail","binary_version":"6.3.26-1"},{"binary_name":"fetchmailconf","binary_version":"6.3.26-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2011/UBUNTU-CVE-2011-1947.json"}}],"schema_version":"1.7.3","severity":[{"type":"Ubuntu","score":"low"}]}