2022-08-28
ALT-BU-2022-5851-1
Branch p10 update bulletin.
Closed vulnerabilities
Published: 2021-07-29
BDU:2021-03928
Уязвимость утилиты приема и пересылки почты fetchmail, связанная с некорректной инициализацией ресурса, позволяющая нарушителю получить доступ к конфиденциальной информации
Severity: MEDIUM (6.1)
Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
References:
Published: 2021-07-30
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2021-36386
report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.
Severity: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References:
- http://www.openwall.com/lists/oss-security/2021/07/28/5
- http://www.openwall.com/lists/oss-security/2021/07/28/5
- [oss-security] 20210809 fetchmail 6.4.21 released/regression fix for 6.4.20's security fix, and UPDATE: fetchmail <= 6.4.19 security announcement 2021-01 (CVE-2021-36386)
- [oss-security] 20210809 fetchmail 6.4.21 released/regression fix for 6.4.20's security fix, and UPDATE: fetchmail <= 6.4.19 security announcement 2021-01 (CVE-2021-36386)
- FEDORA-2021-b904d99ce5
- FEDORA-2021-b904d99ce5
- FEDORA-2021-47893f53ed
- FEDORA-2021-47893f53ed
- GLSA-202209-14
- GLSA-202209-14
- https://www.fetchmail.info/fetchmail-SA-2021-01.txt
- https://www.fetchmail.info/fetchmail-SA-2021-01.txt
- https://www.fetchmail.info/security.html
- https://www.fetchmail.info/security.html
Published: 2021-08-30
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2021-39272
Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.
Severity: MEDIUM (5.9)
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
References:
- http://www.openwall.com/lists/oss-security/2021/08/27/3
- http://www.openwall.com/lists/oss-security/2021/08/27/3
- FEDORA-2021-ddefbdbb46
- FEDORA-2021-ddefbdbb46
- FEDORA-2021-e61a978fef
- FEDORA-2021-e61a978fef
- FEDORA-2021-9998719311
- FEDORA-2021-9998719311
- https://nostarttls.secvuln.info/
- https://nostarttls.secvuln.info/
- GLSA-202209-14
- GLSA-202209-14
- https://www.fetchmail.info/security.html
- https://www.fetchmail.info/security.html