QID 375766

Date Published: 2021-08-12

QID 375766: Fetchmail Denial of Service Vulnerability (fetchmail-SA-2021-01)

Fetchmail is an open source software utility for POSIX-compliant operating systems which is used to retrieve e-mail from a remote POP3, IMAP, ETRN or ODMR mail server to the user's local system.

Affected Versions:
fetchmail releases up to and including 6.3.8
fetchmail releases 6.3.17 up to including 6.4.19

**Note: fetchmail releases 6.3.9 to 6.3.16 Not affected

QID Detection Logic (Authenticated):
This QID checks for vulnerable version of Fetchmail

Successful exploit by attackers can cause a denial of service or possibly have unspecified other impact via long error messages

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Patch:
    Upgrade to Fetchmail Version 6.4.20 and newer, recompile and reinstall it. Further instructions on applying the patch can be found at fetchmail-SA-2021-01 Advisory.

    Vendor References

    CVEs related to QID 375766

    Software Advisories
    Advisory ID Software Component Link
    fetchmail-SA-2021-01 URL Logo www.fetchmail.info/fetchmail-SA-2021-01.txt