CVE-2021-39272
Summary
| CVE | CVE-2021-39272 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-30 06:15:00 UTC |
| Updated | 2023-11-07 03:37:00 UTC |
| Description | Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159824 Oracle Enterprise Linux Security Update for fetchmail (ELSA-2022-1964)
- 182075 Debian Security Update for fetchmail (CVE-2021-39272)
- 240272 Red Hat Update for fetchmail (RHSA-2022:1964)
- 281929 Fedora Security Update for fetchmail (FEDORA-2021-9998719311)
- 281930 Fedora Security Update for fetchmail (FEDORA-2021-ddefbdbb46)
- 296061 Oracle Solaris 11.4 Support Repository Update (SRU) 42.113.1 Missing (CPUJAN2022)
- 501844 Alpine Linux Security Update for fetchmail
- 504739 Alpine Linux Security Update for fetchmail
- 690051 Free Berkeley Software Distribution (FreeBSD) Security Update for fetchmail (1d6410e8-06c1-11ec-a35d-03ca114d16d6)
- 710623 Gentoo Linux Fetchmail Multiple Vulnerabilities (GLSA 202209-14)
- 751263 SUSE Enterprise Linux Security Update for fetchmail (SUSE-SU-2021:3492-1)
- 751269 OpenSUSE Security Update for fetchmail (openSUSE-SU-2021:3493-1)
- 751301 OpenSUSE Security Update for fetchmail (openSUSE-SU-2021:1416-1)
- 751492 SUSE Enterprise Linux Security Update for fetchmail (SUSE-SU-2021:4018-1)
- 751503 OpenSUSE Security Update for fetchmail (openSUSE-SU-2021:4018-1)
- 751527 OpenSUSE Security Update for fetchmail (openSUSE-SU-2021:1591-1)
- 901402 Common Base Linux Mariner (CBL-Mariner) Security Update for fetchmail (7227)
- 907296 Common Base Linux Mariner (CBL-Mariner) Security Update for fetchmail (7227-1)
- 940538 AlmaLinux Security Update for fetchmail (ALSA-2022:1964)
- 960318 Rocky Linux Security Update for fetchmail (RLSA-2022:1964)