AZL-105066

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105066.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-105066
Upstream
Published
2026-09-21T15:17:38Z
Modified
2026-10-01T14:15:23Z
Summary
CVE-2026-94184 affecting package fetchmail 6.4.39-2
Details

A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixed stack buffer while building the NTLM authenticate response. This may lead to remote code execution depending on stack-frame layout, or to authentication failure or process termination under memory hardening.

References

Affected packages

Azure Linux:3 / fetchmail

Package

Name
fetchmail
Purl
pkg:rpm/azure-linux/fetchmail

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
6.4.39-2

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105066.json"