MGASA-2021-0391 - Updated fetchmail packages fix security vulnerability

Publication date: 06 Aug 2021
URL: https://advisories.mageia.org/MGASA-2021-0391.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2021-36386

Updated fetchmail packages fix security vulnerability:

report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits
initialization of the vsnprintf va_list argument, which might allow mail
servers to cause a denial of service or possibly have unspecified other
impact via long error messages (CVE-2021-36386).

References:
- https://bugs.mageia.org/show_bug.cgi?id=29297
- https://www.fetchmail.info/fetchmail-SA-2021-01.txt
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36386

SRPMS:
- 8/core/fetchmail-6.4.8-4.1.mga8

Mageia 2021-0391: fetchmail security update

Updated fetchmail packages fix security vulnerability: report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which...

Summary

Updated fetchmail packages fix security vulnerability:
report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages (CVE-2021-36386).

References

- https://bugs.mageia.org/show_bug.cgi?id=29297

- https://www.fetchmail.info/fetchmail-SA-2021-01.txt

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36386

Resolution

MGASA-2021-0391 - Updated fetchmail packages fix security vulnerability

SRPMS

- 8/core/fetchmail-6.4.8-4.1.mga8

Severity
Publication date: 06 Aug 2021
URL: https://advisories.mageia.org/MGASA-2021-0391.html
Type: security
CVE: CVE-2021-36386

Related News