CVE-2005-3088

fetchmailconf before 1.49 in fetchmail 6.2.0, 6.2.5 and 6.2.5.2 creates configuration files with insecure world-readable permissions, which allows local users to obtain sensitive information such as passwords.

Published: 2005-10-27 Last update: 2026-04-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2005-3088 is rated Low Risk (21.3/100): CVSS Low severity, with low exploitation likelihood (EPSS 0.45%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2005-3088

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.09% 0.45% +0.36%
2 2025-03-17 0.42% 0.09% -0.33%
3 2024-12-17 0.42%

Full EPSS history (6 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2005-3088

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
2.1 2.0 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:N)
No availability impact.
3.9 2.9 [email protected]

Weakness enumeration for CVE-2005-3088

OS Trackers for CVE-2005-3088

vendor priority summary link
debian low CVE-2005-3088 low priority: Debian including 1 source packages (fetchmail), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2005-3088
gentoo normal CVE-2005-3088: 1 GLSA(s) (200511-06), 1 atom(s) (net-mail/fetchmail); latest impact normal. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2005-3088
redhat low https://access.redhat.com/security/cve/CVE-2005-3088
ubuntu medium CVE-2005-3088 medium priority: Ubuntu including 1 source packages (fetchmail), 4 status rows across 4 suites (dapper, edgy, feisty, upstream): released 3, needs-triage 1. https://ubuntu.com/security/CVE-2005-3088

Affected software / configurations for CVE-2005-3088

Vendor Product Version Raw CPE
fetchmail fetchmail 6.2.0 cpe:2.3:a:fetchmail:fetchmail:6.2.0:*:*:*:*:*:*:*
fetchmail fetchmail 6.2.5 cpe:2.3:a:fetchmail:fetchmail:6.2.5:*:*:*:*:*:*:*
fetchmail fetchmail 6.2.5.2 cpe:2.3:a:fetchmail:fetchmail:6.2.5.2:*:*:*:*:*:*:*

References for CVE-2005-3088

URL Tags
http://fetchmail.berlios.de/fetchmail-SA-2005-02.txt Patch Vendor Advisory
http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html
http://marc.info/?l=bugtraq&m=113042785902031&w=2
http://secunia.com/advisories/17293 Patch Vendor Advisory
http://secunia.com/advisories/17349 Vendor Advisory
http://secunia.com/advisories/17446 Vendor Advisory
http://secunia.com/advisories/17491 Vendor Advisory
http://secunia.com/advisories/17495 Vendor Advisory
http://secunia.com/advisories/17631 Vendor Advisory
http://secunia.com/advisories/18895 Vendor Advisory
http://secunia.com/advisories/21253 Vendor Advisory
http://securitytracker.com/id?1015114
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.443499
http://www.debian.org/security/2005/dsa-900
http://www.gentoo.org/security/en/glsa/glsa-200511-06.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2005:209
http://www.osvdb.org/20267
http://www.redhat.com/support/errata/RHSA-2005-823.html
http://www.securityfocus.com/bid/15179 Patch
http://www.securityfocus.com/bid/19289
http://www.us-cert.gov/cas/techalerts/TA06-214A.html US Government Resource
http://www.vupen.com/english/advisories/2005/2182
http://www.vupen.com/english/advisories/2006/3101
https://usn.ubuntu.com/215-1/
cvelogic Threat Intelligence