PT-2021-3695 · Fetchmail+8 · Fetchmail+8
Christian Herdtweck
·
Published
2021-07-29
·
Updated
2024-08-23
·
CVE-2021-36386
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Fetchmail versions prior to 6.4.20
Description
The issue is related to the
report vbuild function in report.c, which sometimes omits initialization of the vsnprintf va list argument. This might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. It is unclear whether the use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user. The vulnerability may also allow an attacker to gain access to confidential information.Recommendations
For Fetchmail versions prior to 6.4.20, update to version 6.4.20 or later to resolve the issue. As a temporary workaround, consider restricting the length of error messages received from mail servers to minimize the risk of exploitation.
Fix
DoS
Improper Initialization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Fetchmail
Red Hat
Red Os
Rocky Linux
Suse