OESA-2021-1314
Dashboard / Vulnerabilities / OESA-2021-1314
Summary: fetchmail security update
Details: Fetchmail is a remote mail retrieval and forwarding utility intended for use over on-demand TCP/IP links, like SLIP or PPP connections. Fetchmail supports every remote-mail protocol currently in use on the Internet (POP2, POP3, RPOP, APOP, KPOP, all IMAPs, ESMTP ETRN, IPv6, and IPSEC) for retrieval. Then Fetchmail forwards the mail through SMTP so you can read it through your favorite mail client. Install fetchmail if you need to retrieve mail over SLIP or PPP connections. Security Fix(es): report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.(CVE-2021-36386)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1314, https://nvd.nist.gov/vuln/detail/CVE-2021-36386
Affected packages
Package
Name: fetchmail
Purl: pkg:rpm/openEuler/fetchmail&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
