OESA-2021-1314

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2021-1314
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2021-1314.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2021-1314
Upstream
Published
2021-08-20T11:04:33Z
Modified
2026-08-18T01:15:56Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
fetchmail security update
Details

Fetchmail is a remote mail retrieval and forwarding utility intended for use over on-demand TCP/IP links, like SLIP or PPP connections. Fetchmail supports every remote-mail protocol currently in use on the Internet (POP2, POP3, RPOP, APOP, KPOP, all IMAPs, ESMTP ETRN, IPv6, and IPSEC) for retrieval. Then Fetchmail forwards the mail through SMTP so you can read it through your favorite mail client. Install fetchmail if you need to retrieve mail over SLIP or PPP connections.

Security Fix(es):

report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.(CVE-2021-36386)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP1 / fetchmail

Package

Name
fetchmail
Purl
pkg:rpm/openEuler/fetchmail&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.4.20-1.oe1

Ecosystem specific

{
    "aarch64": [
        "fetchmail-debuginfo-6.4.20-1.oe1.aarch64.rpm",
        "fetchmail-debugsource-6.4.20-1.oe1.aarch64.rpm",
        "fetchmail-6.4.20-1.oe1.aarch64.rpm"
    ],
    "noarch": [
        "fetchmail-help-6.4.20-1.oe1.noarch.rpm"
    ],
    "src": [
        "fetchmail-6.4.20-1.oe1.src.rpm"
    ],
    "x86_64": [
        "fetchmail-debugsource-6.4.20-1.oe1.x86_64.rpm",
        "fetchmail-6.4.20-1.oe1.x86_64.rpm",
        "fetchmail-debuginfo-6.4.20-1.oe1.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2021-1314.json"

openEuler:20.03-LTS-SP2 / fetchmail

Package

Name
fetchmail
Purl
pkg:rpm/openEuler/fetchmail&distro=openEuler-20.03-LTS-SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.4.20-1.oe1

Ecosystem specific

{
    "aarch64": [
        "fetchmail-6.4.20-1.oe1.aarch64.rpm",
        "fetchmail-debuginfo-6.4.20-1.oe1.aarch64.rpm",
        "fetchmail-debugsource-6.4.20-1.oe1.aarch64.rpm"
    ],
    "noarch": [
        "fetchmail-help-6.4.20-1.oe1.noarch.rpm"
    ],
    "src": [
        "fetchmail-6.4.20-1.oe1.src.rpm"
    ],
    "x86_64": [
        "fetchmail-debugsource-6.4.20-1.oe1.x86_64.rpm",
        "fetchmail-6.4.20-1.oe1.x86_64.rpm",
        "fetchmail-debuginfo-6.4.20-1.oe1.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2021-1314.json"