CVE-2012-3482

Fetchmail 5.0.8 through 6.3.21, when using NTLM authentication in debug mode, allows remote NTLM servers to (1) cause a denial of service (crash and delayed delivery of inbound mail) via a crafted NTLM response that triggers an out-of-bounds read in the base64 decoder, or (2) obtain sensitive information from memory via an NTLM Type 2 message with a crafted Target Name structure, which triggers an out-of-bounds read.

Published: 2012-12-21 Last update: 2026-04-29 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2012-3482 is rated Moderate Risk (51.2/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.87%). Core evidence: EPSS rose +1.15% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2012-3482

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.72% 1.87% +1.15%
2 2025-12-07 1.08% 0.72% -0.36%
3 2025-07-13 1.08%

Full EPSS history (10 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2012-3482

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.8 2.0 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:P)
Partial availability impact.
8.6 4.9 [email protected]

Weakness enumeration for CVE-2012-3482

OS Trackers for CVE-2012-3482

vendor priority summary link
debian low CVE-2012-3482 low priority: Debian including 1 source packages (fetchmail), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2012-3482
redhat low https://access.redhat.com/security/cve/CVE-2012-3482
suse medium CVE-2012-3482 severity moderate: SUSE including 13 source package names (fetchmail-6.3.26-12.3, fetchmail-6.3.26-13.4, …), 41 product×package rows across 27 product lines (SUSE Linux Enterprise Desktop 11 SP4, SUSE Linux Enterprise Desktop 12, … (27 product lines)): Fixed 41. https://www.suse.com/security/cve/CVE-2012-3482/
ubuntu low CVE-2012-3482 low priority: Ubuntu including 1 source packages (fetchmail), 26 status rows across 26 suites (artful, bionic, cosmic, disco, eoan, focal, groovy, hardy, hirsute, impish, jammy, lucid, natty, oneiric, precise, quantal, raring, saucy, trusty, upstream, utopic, vivid, wily, xenial, yakkety, zesty): ignored 18, not-affected 6, DNE 1, released 1. https://ubuntu.com/security/CVE-2012-3482

Affected software / configurations for CVE-2012-3482

Vendor Product Version Raw CPE
fetchmail fetchmail 5.0.8 cpe:2.3:a:fetchmail:fetchmail:5.0.8:*:*:*:*:*:*:*
fetchmail fetchmail 5.1.0 cpe:2.3:a:fetchmail:fetchmail:5.1.0:*:*:*:*:*:*:*
fetchmail fetchmail 5.1.4 cpe:2.3:a:fetchmail:fetchmail:5.1.4:*:*:*:*:*:*:*
fetchmail fetchmail 5.2.0 cpe:2.3:a:fetchmail:fetchmail:5.2.0:*:*:*:*:*:*:*
fetchmail fetchmail 5.2.1 cpe:2.3:a:fetchmail:fetchmail:5.2.1:*:*:*:*:*:*:*
fetchmail fetchmail 5.2.3 cpe:2.3:a:fetchmail:fetchmail:5.2.3:*:*:*:*:*:*:*
fetchmail fetchmail 5.2.4 cpe:2.3:a:fetchmail:fetchmail:5.2.4:*:*:*:*:*:*:*
fetchmail fetchmail 5.2.7 cpe:2.3:a:fetchmail:fetchmail:5.2.7:*:*:*:*:*:*:*
fetchmail fetchmail 5.2.8 cpe:2.3:a:fetchmail:fetchmail:5.2.8:*:*:*:*:*:*:*
fetchmail fetchmail 5.3.0 cpe:2.3:a:fetchmail:fetchmail:5.3.0:*:*:*:*:*:*:*
fetchmail fetchmail 5.3.1 cpe:2.3:a:fetchmail:fetchmail:5.3.1:*:*:*:*:*:*:*
fetchmail fetchmail 5.3.3 cpe:2.3:a:fetchmail:fetchmail:5.3.3:*:*:*:*:*:*:*
fetchmail fetchmail 5.3.8 cpe:2.3:a:fetchmail:fetchmail:5.3.8:*:*:*:*:*:*:*
fetchmail fetchmail 5.4.0 cpe:2.3:a:fetchmail:fetchmail:5.4.0:*:*:*:*:*:*:*
fetchmail fetchmail 5.4.3 cpe:2.3:a:fetchmail:fetchmail:5.4.3:*:*:*:*:*:*:*
fetchmail fetchmail 5.4.4 cpe:2.3:a:fetchmail:fetchmail:5.4.4:*:*:*:*:*:*:*
fetchmail fetchmail 5.4.5 cpe:2.3:a:fetchmail:fetchmail:5.4.5:*:*:*:*:*:*:*
fetchmail fetchmail 5.5.0 cpe:2.3:a:fetchmail:fetchmail:5.5.0:*:*:*:*:*:*:*
fetchmail fetchmail 5.5.2 cpe:2.3:a:fetchmail:fetchmail:5.5.2:*:*:*:*:*:*:*
fetchmail fetchmail 5.5.3 cpe:2.3:a:fetchmail:fetchmail:5.5.3:*:*:*:*:*:*:*
fetchmail fetchmail 5.5.5 cpe:2.3:a:fetchmail:fetchmail:5.5.5:*:*:*:*:*:*:*
fetchmail fetchmail 5.5.6 cpe:2.3:a:fetchmail:fetchmail:5.5.6:*:*:*:*:*:*:*
fetchmail fetchmail 5.6.0 cpe:2.3:a:fetchmail:fetchmail:5.6.0:*:*:*:*:*:*:*
fetchmail fetchmail 5.7.0 cpe:2.3:a:fetchmail:fetchmail:5.7.0:*:*:*:*:*:*:*
fetchmail fetchmail 5.7.2 cpe:2.3:a:fetchmail:fetchmail:5.7.2:*:*:*:*:*:*:*
fetchmail fetchmail 5.7.4 cpe:2.3:a:fetchmail:fetchmail:5.7.4:*:*:*:*:*:*:*
fetchmail fetchmail 5.8 cpe:2.3:a:fetchmail:fetchmail:5.8:*:*:*:*:*:*:*
fetchmail fetchmail 5.8.1 cpe:2.3:a:fetchmail:fetchmail:5.8.1:*:*:*:*:*:*:*
fetchmail fetchmail 5.8.2 cpe:2.3:a:fetchmail:fetchmail:5.8.2:*:*:*:*:*:*:*
fetchmail fetchmail 5.8.3 cpe:2.3:a:fetchmail:fetchmail:5.8.3:*:*:*:*:*:*:*
fetchmail fetchmail 5.8.4 cpe:2.3:a:fetchmail:fetchmail:5.8.4:*:*:*:*:*:*:*
fetchmail fetchmail 5.8.5 cpe:2.3:a:fetchmail:fetchmail:5.8.5:*:*:*:*:*:*:*
fetchmail fetchmail 5.8.6 cpe:2.3:a:fetchmail:fetchmail:5.8.6:*:*:*:*:*:*:*
fetchmail fetchmail 5.8.11 cpe:2.3:a:fetchmail:fetchmail:5.8.11:*:*:*:*:*:*:*
fetchmail fetchmail 5.8.13 cpe:2.3:a:fetchmail:fetchmail:5.8.13:*:*:*:*:*:*:*
fetchmail fetchmail 5.8.14 cpe:2.3:a:fetchmail:fetchmail:5.8.14:*:*:*:*:*:*:*
fetchmail fetchmail 5.8.17 cpe:2.3:a:fetchmail:fetchmail:5.8.17:*:*:*:*:*:*:*
fetchmail fetchmail 5.9.0 cpe:2.3:a:fetchmail:fetchmail:5.9.0:*:*:*:*:*:*:*
fetchmail fetchmail 5.9.4 cpe:2.3:a:fetchmail:fetchmail:5.9.4:*:*:*:*:*:*:*
fetchmail fetchmail 5.9.5 cpe:2.3:a:fetchmail:fetchmail:5.9.5:*:*:*:*:*:*:*
fetchmail fetchmail 5.9.8 cpe:2.3:a:fetchmail:fetchmail:5.9.8:*:*:*:*:*:*:*
fetchmail fetchmail 5.9.10 cpe:2.3:a:fetchmail:fetchmail:5.9.10:*:*:*:*:*:*:*
fetchmail fetchmail 5.9.11 cpe:2.3:a:fetchmail:fetchmail:5.9.11:*:*:*:*:*:*:*
fetchmail fetchmail 5.9.13 cpe:2.3:a:fetchmail:fetchmail:5.9.13:*:*:*:*:*:*:*
fetchmail fetchmail 6.0.0 cpe:2.3:a:fetchmail:fetchmail:6.0.0:*:*:*:*:*:*:*
fetchmail fetchmail 6.1.0 cpe:2.3:a:fetchmail:fetchmail:6.1.0:*:*:*:*:*:*:*
fetchmail fetchmail 6.1.3 cpe:2.3:a:fetchmail:fetchmail:6.1.3:*:*:*:*:*:*:*
fetchmail fetchmail 6.2.0 cpe:2.3:a:fetchmail:fetchmail:6.2.0:*:*:*:*:*:*:*
fetchmail fetchmail 6.2.1 cpe:2.3:a:fetchmail:fetchmail:6.2.1:*:*:*:*:*:*:*
fetchmail fetchmail 6.2.2 cpe:2.3:a:fetchmail:fetchmail:6.2.2:*:*:*:*:*:*:*
fetchmail fetchmail 6.2.3 cpe:2.3:a:fetchmail:fetchmail:6.2.3:*:*:*:*:*:*:*
fetchmail fetchmail 6.2.4 cpe:2.3:a:fetchmail:fetchmail:6.2.4:*:*:*:*:*:*:*
fetchmail fetchmail 6.2.5 cpe:2.3:a:fetchmail:fetchmail:6.2.5:*:*:*:*:*:*:*
fetchmail fetchmail 6.2.5.1 cpe:2.3:a:fetchmail:fetchmail:6.2.5.1:*:*:*:*:*:*:*
fetchmail fetchmail 6.2.5.2 cpe:2.3:a:fetchmail:fetchmail:6.2.5.2:*:*:*:*:*:*:*
fetchmail fetchmail 6.2.5.4 cpe:2.3:a:fetchmail:fetchmail:6.2.5.4:*:*:*:*:*:*:*
fetchmail fetchmail 6.2.6 cpe:2.3:a:fetchmail:fetchmail:6.2.6:pre4:*:*:*:*:*:*
fetchmail fetchmail 6.2.6 cpe:2.3:a:fetchmail:fetchmail:6.2.6:pre8:*:*:*:*:*:*
fetchmail fetchmail 6.2.6 cpe:2.3:a:fetchmail:fetchmail:6.2.6:pre9:*:*:*:*:*:*
fetchmail fetchmail 6.2.9 cpe:2.3:a:fetchmail:fetchmail:6.2.9:rc10:*:*:*:*:*:*
fetchmail fetchmail 6.2.9 cpe:2.3:a:fetchmail:fetchmail:6.2.9:rc3:*:*:*:*:*:*
fetchmail fetchmail 6.2.9 cpe:2.3:a:fetchmail:fetchmail:6.2.9:rc4:*:*:*:*:*:*
fetchmail fetchmail 6.2.9 cpe:2.3:a:fetchmail:fetchmail:6.2.9:rc5:*:*:*:*:*:*
fetchmail fetchmail 6.2.9 cpe:2.3:a:fetchmail:fetchmail:6.2.9:rc7:*:*:*:*:*:*
fetchmail fetchmail 6.2.9 cpe:2.3:a:fetchmail:fetchmail:6.2.9:rc8:*:*:*:*:*:*
fetchmail fetchmail 6.2.9 cpe:2.3:a:fetchmail:fetchmail:6.2.9:rc9:*:*:*:*:*:*
fetchmail fetchmail 6.3.0 cpe:2.3:a:fetchmail:fetchmail:6.3.0:*:*:*:*:*:*:*
fetchmail fetchmail 6.3.1 cpe:2.3:a:fetchmail:fetchmail:6.3.1:*:*:*:*:*:*:*
fetchmail fetchmail 6.3.2 cpe:2.3:a:fetchmail:fetchmail:6.3.2:*:*:*:*:*:*:*
fetchmail fetchmail 6.3.3 cpe:2.3:a:fetchmail:fetchmail:6.3.3:*:*:*:*:*:*:*
fetchmail fetchmail 6.3.4 cpe:2.3:a:fetchmail:fetchmail:6.3.4:*:*:*:*:*:*:*
fetchmail fetchmail 6.3.5 cpe:2.3:a:fetchmail:fetchmail:6.3.5:*:*:*:*:*:*:*
fetchmail fetchmail 6.3.6 cpe:2.3:a:fetchmail:fetchmail:6.3.6:*:*:*:*:*:*:*
fetchmail fetchmail 6.3.6 cpe:2.3:a:fetchmail:fetchmail:6.3.6:rc1:*:*:*:*:*:*
fetchmail fetchmail 6.3.6 cpe:2.3:a:fetchmail:fetchmail:6.3.6:rc2:*:*:*:*:*:*
fetchmail fetchmail 6.3.6 cpe:2.3:a:fetchmail:fetchmail:6.3.6:rc3:*:*:*:*:*:*
fetchmail fetchmail 6.3.6 cpe:2.3:a:fetchmail:fetchmail:6.3.6:rc4:*:*:*:*:*:*
fetchmail fetchmail 6.3.6 cpe:2.3:a:fetchmail:fetchmail:6.3.6:rc5:*:*:*:*:*:*
fetchmail fetchmail 6.3.7 cpe:2.3:a:fetchmail:fetchmail:6.3.7:*:*:*:*:*:*:*
fetchmail fetchmail 6.3.8 cpe:2.3:a:fetchmail:fetchmail:6.3.8:*:*:*:*:*:*:*

References for CVE-2012-3482

cvelogic Threat Intelligence