Opened 12 months ago

Closed 12 months ago

Last modified 8 months ago

#22228 closed enhancement (fixed)

fetchmail-6.5.6

Reported by: Bruce Dubbs Owned by: Douglas R. Reno
Priority: elevated Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (5)

comment:1 by Joe Locash, 12 months ago

Priority: normal → elevated

comment:2 by Douglas R. Reno, 12 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:3 by Douglas R. Reno, 12 months ago

Release notes:

Fetchmail 6.5.6 is the seventh fetchmail 6.5 release on 2025-10-03 and fixes 
CVE-2025-61962, a security bug in the SMTP AUTH client code, see fetchmail-
SA-2025-01.txt for details. It also fixes excess timestamp bugs on the console output 
and can automatically render domain literals for SMTP recipients.

Security information:

fetchmail-SA-2025-01: SMTP AUTH denial of service

Topics:		fetchmail SMTP client can crash when authenticating

Author:		Matthias Andree
Version:	1.1
Announced:	2025-10-03
Type:		failure to validate network input in certain configurations
Impact:		fetchmail tries to read from address 1 and can crash
Severity:	moderate

URL:		https://www.fetchmail.info/fetchmail-SA-2025-01.txt
Project URL:	https://www.fetchmail.info/
CVE Name:	CVE-2025-61962

Affects:	- fetchmail releases up to and including 6.5.5
		- fetchmail 7.0.0 pre-releases

Not affected:	- fetchmail 6.5 releases 6.5.6 and newer

Introduced in:	2002-03-09 fetchmail release 5.9.9 added SMTP AUTH

Corrected in:	2025-10-03 Git commit 4c3cebfa4e659fb778ca2cae0ccb3f69201609a8
		2025-10-03 fetchmail release 6.5.6

History:	1.0 2025-10-03 initial announcement
		1.1 2025-10-04 CVE ID added above


1. Background
=============

fetchmail is a software package to retrieve mail from remote POP3, IMAP,
ETRN or ODMR servers and forward it to local SMTP, LMTP servers or
message delivery agents.

fetchmail defaults to using the SMTP server on "localhost"
and to not attempting to authenticate, unless configured otherwise.

fetchmail also supports a "daemon" mode, where it runs over extended time
and periodically polls the upstream servers.  This can detach fetchmail
from the controlling terminal into the background, or - with a "nodetach" setting
- - keep attached to the controlling terminal, which also eases use by
service supervisors.


2. Problem description and Impact
=================================

fetchmail's SMTP client, when configured to authenticate [1], is susceptible
to a protocol violation where, when a trusted but malicious or malfunctioning
SMTP server responds to an authentication request with a "334" code but without a
following blank on the line, it will attempt to start reading from memory
address 0x1 to parse the server's SASL challenge. This address is constant and not
under the attacker's control. This event will usually cause a crash of fetchmail.
  If fetchmail in this situation was running in daemon mode, this mode is also
terminated by the crash.

[1] This requires the esmtpname and esmtppassword options to be configured in
the configuration file and the plugout and mda options to be inactive.

As a word of warning, this vulnerability has eluded several static code analyzers.


3. Solutions
============

General recommendation: if running fetchmail in the background or in daemon
mode, ensure that the daemon is supervised and crashes are reported so that
action can be taken about the malfunctioning SMTP server, or on fetchmail's end
to replace local delivery by different server or other means.


3a. Install fetchmail 6.5.6 or newer.

The fetchmail source code is available from
<https://sourceforge.net/projects/fetchmail/files/> and
<https://gitlab.com/fetchmail/fetchmail/-/releases>

The Git-based source code repository is currently published via
https://gitlab.com/fetchmail/fetchmail/-/tree/legacy_6x (primary)
https://sourceforge.net/p/fetchmail/git/ci/legacy_6x/tree/ (copy)


3b. Apply the smtp.c patch from the URL below and rebuild fetchmail:
<https://gitlab.com/fetchmail/fetchmail/-/commit/4c3cebfa4e659fb778ca2cae0ccb3f69201609a8>

comment:4 by Douglas R. Reno, 12 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at b637af31ef9b3dfff64a87f3b39ee645fb13a1b4

SA-12.4-017 issued

comment:5 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

Note: See TracTickets for help on using tickets.