Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Christian Herdtweck

Researcher fromIntra2net AG
#34509of 53,638
7.5Total CVSS
Vulnerabilities · 1
PT-2021-3695
7.5
2021-07-29
Fetchmail · Fetchmail · CVE-2021-36386
**Name of the Vulnerable Software and Affected Versions** Fetchmail versions prior to 6.4.20 **Description** The issue is related to the `report vbuild` function in `report.c`, which sometimes omits initialization of the `vsnprintf` `va list` argument. This might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. It is unclear whether the use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user. The vulnerability may also allow an attacker to gain access to confidential information. **Recommendations** For Fetchmail versions prior to 6.4.20, update to version 6.4.20 or later to resolve the issue. As a temporary workaround, consider restricting the length of error messages received from mail servers to minimize the risk of exploitation.