fetchmail 5.9.9 through 6.3.19 does not properly limit the wait time after issuing a (1) STARTTLS or (2) STLS request, which allows remote servers to cause a denial of service (application hang) by acknowledging the request but not sending additional packets.
Conclusion & alert: CVE-2011-1947 is rated Moderate Risk (49.1/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 2.55%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 2.44% | 2.55% | +0.11% |
| 2 | 2025-07-13 | 2.19% | 2.44% | +0.25% |
| 3 | 2025-03-30 | — | 2.19% | — |
Full EPSS history (7 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2011-1947 unimportant priority: Debian including 1 source packages (fetchmail), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2011-1947 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2011-1947 |
suse
|
medium | CVE-2011-1947 severity moderate: SUSE including 13 source package names (fetchmail-6.3.26-12.3, fetchmail-6.3.26-13.4, …), 40 product×package rows across 26 product lines (SUSE Linux Enterprise Desktop 12, SUSE Linux Enterprise Desktop 12 SP1, … (26 product lines)): Fixed 40. | https://www.suse.com/security/cve/CVE-2011-1947/ |
ubuntu
|
low | CVE-2011-1947 low priority: Ubuntu including 1 source packages (fetchmail), 27 status rows across 27 suites (artful, bionic, cosmic, disco, eoan, focal, groovy, hardy, hirsute, impish, jammy, lucid, maverick, natty, oneiric, precise, quantal, raring, saucy, trusty, upstream, utopic, vivid, wily, xenial, yakkety, zesty): ignored 19, not-affected 6, DNE 1, pending 1. | https://ubuntu.com/security/CVE-2011-1947 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| fetchmail | fetchmail | 5.9.9 | cpe:2.3:a:fetchmail:fetchmail:5.9.9:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 5.9.10 | cpe:2.3:a:fetchmail:fetchmail:5.9.10:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 5.9.11 | cpe:2.3:a:fetchmail:fetchmail:5.9.11:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 5.9.13 | cpe:2.3:a:fetchmail:fetchmail:5.9.13:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.0.0 | cpe:2.3:a:fetchmail:fetchmail:6.0.0:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.1.0 | cpe:2.3:a:fetchmail:fetchmail:6.1.0:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.1.3 | cpe:2.3:a:fetchmail:fetchmail:6.1.3:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.2.0 | cpe:2.3:a:fetchmail:fetchmail:6.2.0:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.2.1 | cpe:2.3:a:fetchmail:fetchmail:6.2.1:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.2.2 | cpe:2.3:a:fetchmail:fetchmail:6.2.2:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.2.3 | cpe:2.3:a:fetchmail:fetchmail:6.2.3:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.2.4 | cpe:2.3:a:fetchmail:fetchmail:6.2.4:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.2.5 | cpe:2.3:a:fetchmail:fetchmail:6.2.5:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.2.5.1 | cpe:2.3:a:fetchmail:fetchmail:6.2.5.1:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.2.5.2 | cpe:2.3:a:fetchmail:fetchmail:6.2.5.2:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.2.5.4 | cpe:2.3:a:fetchmail:fetchmail:6.2.5.4:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.2.6 | cpe:2.3:a:fetchmail:fetchmail:6.2.6:pre4:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.2.6 | cpe:2.3:a:fetchmail:fetchmail:6.2.6:pre8:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.2.6 | cpe:2.3:a:fetchmail:fetchmail:6.2.6:pre9:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.2.9 | cpe:2.3:a:fetchmail:fetchmail:6.2.9:rc10:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.2.9 | cpe:2.3:a:fetchmail:fetchmail:6.2.9:rc3:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.2.9 | cpe:2.3:a:fetchmail:fetchmail:6.2.9:rc4:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.2.9 | cpe:2.3:a:fetchmail:fetchmail:6.2.9:rc5:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.2.9 | cpe:2.3:a:fetchmail:fetchmail:6.2.9:rc7:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.2.9 | cpe:2.3:a:fetchmail:fetchmail:6.2.9:rc8:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.2.9 | cpe:2.3:a:fetchmail:fetchmail:6.2.9:rc9:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.0 | cpe:2.3:a:fetchmail:fetchmail:6.3.0:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.1 | cpe:2.3:a:fetchmail:fetchmail:6.3.1:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.2 | cpe:2.3:a:fetchmail:fetchmail:6.3.2:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.3 | cpe:2.3:a:fetchmail:fetchmail:6.3.3:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.4 | cpe:2.3:a:fetchmail:fetchmail:6.3.4:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.5 | cpe:2.3:a:fetchmail:fetchmail:6.3.5:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.6 | cpe:2.3:a:fetchmail:fetchmail:6.3.6:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.6 | cpe:2.3:a:fetchmail:fetchmail:6.3.6:rc1:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.6 | cpe:2.3:a:fetchmail:fetchmail:6.3.6:rc2:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.6 | cpe:2.3:a:fetchmail:fetchmail:6.3.6:rc3:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.6 | cpe:2.3:a:fetchmail:fetchmail:6.3.6:rc4:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.6 | cpe:2.3:a:fetchmail:fetchmail:6.3.6:rc5:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.7 | cpe:2.3:a:fetchmail:fetchmail:6.3.7:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.8 | cpe:2.3:a:fetchmail:fetchmail:6.3.8:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.9 | cpe:2.3:a:fetchmail:fetchmail:6.3.9:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.9 | cpe:2.3:a:fetchmail:fetchmail:6.3.9:rc2:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.10 | cpe:2.3:a:fetchmail:fetchmail:6.3.10:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.11 | cpe:2.3:a:fetchmail:fetchmail:6.3.11:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.12 | cpe:2.3:a:fetchmail:fetchmail:6.3.12:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.13 | cpe:2.3:a:fetchmail:fetchmail:6.3.13:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.14 | cpe:2.3:a:fetchmail:fetchmail:6.3.14:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.15 | cpe:2.3:a:fetchmail:fetchmail:6.3.15:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.16 | cpe:2.3:a:fetchmail:fetchmail:6.3.16:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.17 | cpe:2.3:a:fetchmail:fetchmail:6.3.17:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.18 | cpe:2.3:a:fetchmail:fetchmail:6.3.18:*:*:*:*:*:*:* |
| fetchmail | fetchmail | 6.3.19 | cpe:2.3:a:fetchmail:fetchmail:6.3.19:*:*:*:*:*:*:* |