PT-2021-3695 · Fetchmail+8 · Fetchmail+8

Christian Herdtweck

·

Published

2021-07-29

·

Updated

2024-08-23

·

CVE-2021-36386

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Fetchmail versions prior to 6.4.20
Description The issue is related to the report vbuild function in report.c, which sometimes omits initialization of the vsnprintf va list argument. This might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. It is unclear whether the use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user. The vulnerability may also allow an attacker to gain access to confidential information.
Recommendations For Fetchmail versions prior to 6.4.20, update to version 6.4.20 or later to resolve the issue. As a temporary workaround, consider restricting the length of error messages received from mail servers to minimize the risk of exploitation.

Fix

DoS

Improper Initialization

Weakness Enumeration

Related Identifiers

ALSA-2022:1964
ALT-PU-2021-3301
ALT-PU-2022-2513
AZL-7226
BDU:2021-03928
CESA-2022_1964
CVE-2021-36386
MGASA-2021-0391
OESA-2021-1314
OPENSUSE-SU-2021:1183-1
OPENSUSE-SU-2021:1591-1
OPENSUSE-SU-2021:2791-1
OPENSUSE-SU-2021:4018-1
OPENSUSE-SU-2021_1183-1
OPENSUSE-SU-2021_1591-1
OPENSUSE-SU-2021_2791-1
OPENSUSE-SU-2021_4018-1
OPENSUSE-SU-2024:10753-1
RHSA-2022:1964
RHSA-2022_1964
RLSA-2022:1964
SUSE-SU-2021:2771-1
SUSE-SU-2021:2791-1
SUSE-SU-2021:4018-1
SUSE-SU-2021_2771-1
SUSE-SU-2021_2791-1
SUSE-SU-2021_4018-1
SUSE-SU-2024:3006-1
SUSE-SU-2024_3006-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Fetchmail
Red Hat
Red Os
Rocky Linux
Suse