Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Mageia 8: 2021-0391 Moderate: Fetchmail Denial of Service

mageia
Calendar Grey August 6, 2021
Dist Mageia Esm H88
Updated fetchmail packages fix a vulnerability in Mageia 8 that may cause denial of service via error messages.
Updated fetchmail packages fix security vulnerability: report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which...

Summary

Updated fetchmail packages fix security vulnerability:
report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages (CVE-2021-36386).

References

- https://bugs.mageia.org/show_bug.cgi?id=29297

- https://www.fetchmail.info/fetchmail-SA-2021-01.txt

- https://www.cve.org/CVERecord?id=CVE-2021-36386

Resolution

SRPMS

- 8/core/fetchmail-6.4.8-4.1.mga8

Publication date: 06 Aug 2021
URL: https://advisories.mageia.org/MGASA-2021-0391.html
Type: security
CVE: CVE-2021-36386

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here