CVE-2021-36386
Summary
| CVE | CVE-2021-36386 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-30 14:15:00 UTC |
| Updated | 2023-11-07 03:36:00 UTC |
| Description | report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 34 Update: fetchmail-6.4.20-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Fetchmail: Multiple Vulnerabilities (GLSA 202209-14) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Fetchmail |
MISC |
www.fetchmail.info |
|
| FEDORA-2021-47893f53ed |
FEDORA |
lists.fedoraproject.org |
|
| www.fetchmail.info/fetchmail-SA-2021-01.txt |
CONFIRM |
www.fetchmail.info |
|
| oss-security - ANNOUNCE: fetchmail <= 6.4.19 security announcement 2021-01
(CVE-2021-36386) - fetchmail 6.4.20 released. DoS or information disclosure
in some configurations |
MISC |
www.openwall.com |
|
| [SECURITY] Fedora 33 Update: fetchmail-6.4.20-1.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| oss-security - fetchmail 6.4.21 released/regression fix for 6.4.20's security fix,
and UPDATE: fetchmail <= 6.4.19 security announcement 2021-01
(CVE-2021-36386) |
MLIST |
www.openwall.com |
|
| [SECURITY] Fedora 34 Update: fetchmail-6.4.20-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159824 Oracle Enterprise Linux Security Update for fetchmail (ELSA-2022-1964)
- 180122 Debian Security Update for fetchmail (CVE-2021-36386)
- 240272 Red Hat Update for fetchmail (RHSA-2022:1964)
- 281789 Fedora Security Update for fetchmail (FEDORA-2021-47893f53ed)
- 281790 Fedora Security Update for fetchmail (FEDORA-2021-b904d99ce5)
- 296065 Oracle Solaris 11.4 Support Repository Update (SRU) 39.107.1 Missing (CPUOCT2021)
- 375766 Fetchmail Denial of Service Vulnerability (fetchmail-SA-2021-01)
- 501843 Alpine Linux Security Update for fetchmail
- 504738 Alpine Linux Security Update for fetchmail
- 670948 EulerOS Security Update for fetchmail (EulerOS-SA-2021-2658)
- 670995 EulerOS Security Update for fetchmail (EulerOS-SA-2021-2629)
- 671262 EulerOS Security Update for fetchmail (EulerOS-SA-2022-1162)
- 690072 Free Berkeley Software Distribution (FreeBSD) Security Update for fetchmail (cbfd1874-efea-11eb-8fe9-036bd763ff35)
- 710623 Gentoo Linux Fetchmail Multiple Vulnerabilities (GLSA 202209-14)
- 750976 SUSE Enterprise Linux Security Update for fetchmail (SUSE-SU-2021:2771-1)
- 750990 SUSE Enterprise Linux Security Update for fetchmail (SUSE-SU-2021:2791-1)
- 750998 OpenSUSE Security Update for fetchmail (openSUSE-SU-2021:1183-1)
- 751015 OpenSUSE Security Update for fetchmail (openSUSE-SU-2021:2791-1)
- 751492 SUSE Enterprise Linux Security Update for fetchmail (SUSE-SU-2021:4018-1)
- 751503 OpenSUSE Security Update for fetchmail (openSUSE-SU-2021:4018-1)
- 751527 OpenSUSE Security Update for fetchmail (openSUSE-SU-2021:1591-1)
- 901783 Common Base Linux Mariner (CBL-Mariner) Security Update for fetchmail (7226)
- 907341 Common Base Linux Mariner (CBL-Mariner) Security Update for fetchmail (7226-1)
- 91799 Cygwin fetchmail Package Denial Of Service Vulnerability
- 940538 AlmaLinux Security Update for fetchmail (ALSA-2022:1964)
- 960318 Rocky Linux Security Update for fetchmail (RLSA-2022:1964)