QID 91799

QID 91799: Cygwin fetchmail Package Denial Of Service Vulnerability

Cygwin is a Linux-style operating environment for Microsoft Windows.

CVE-2021-36386: report_vbuild in report.c file in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified another impact via long error messages.

Affected Versions:
Cygwin Fetchmail before 6.4.20.
QID Detection Logic (authenticated):
The QID flags if it finds a vulnerable version of the curl package in installed file. The location of the file is determined by the key "HKLM\SOFTWARE\Cygwin\setup", value "rootdir". The file is present in the <rootdir>\etc\setup folder.

Successful exploitation of this vulnerability could allow denial of service.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has released fixes in Cygwin Pipermail

    CVEs related to QID 91799

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-36386 URL Logo cygwin.com/pipermail/cygwin-announce/2021-July/010144.html