#22228 closed enhancement (fixed)
fetchmail-6.5.6
| Reported by: | Bruce Dubbs | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | elevated | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (5)
comment:1 by , 12 months ago
| Priority: | normal → elevated |
|---|
comment:2 by , 12 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:3 by , 12 months ago
Release notes:
Fetchmail 6.5.6 is the seventh fetchmail 6.5 release on 2025-10-03 and fixes CVE-2025-61962, a security bug in the SMTP AUTH client code, see fetchmail- SA-2025-01.txt for details. It also fixes excess timestamp bugs on the console output and can automatically render domain literals for SMTP recipients.
Security information:
fetchmail-SA-2025-01: SMTP AUTH denial of service Topics: fetchmail SMTP client can crash when authenticating Author: Matthias Andree Version: 1.1 Announced: 2025-10-03 Type: failure to validate network input in certain configurations Impact: fetchmail tries to read from address 1 and can crash Severity: moderate URL: https://www.fetchmail.info/fetchmail-SA-2025-01.txt Project URL: https://www.fetchmail.info/ CVE Name: CVE-2025-61962 Affects: - fetchmail releases up to and including 6.5.5 - fetchmail 7.0.0 pre-releases Not affected: - fetchmail 6.5 releases 6.5.6 and newer Introduced in: 2002-03-09 fetchmail release 5.9.9 added SMTP AUTH Corrected in: 2025-10-03 Git commit 4c3cebfa4e659fb778ca2cae0ccb3f69201609a8 2025-10-03 fetchmail release 6.5.6 History: 1.0 2025-10-03 initial announcement 1.1 2025-10-04 CVE ID added above 1. Background ============= fetchmail is a software package to retrieve mail from remote POP3, IMAP, ETRN or ODMR servers and forward it to local SMTP, LMTP servers or message delivery agents. fetchmail defaults to using the SMTP server on "localhost" and to not attempting to authenticate, unless configured otherwise. fetchmail also supports a "daemon" mode, where it runs over extended time and periodically polls the upstream servers. This can detach fetchmail from the controlling terminal into the background, or - with a "nodetach" setting - - keep attached to the controlling terminal, which also eases use by service supervisors. 2. Problem description and Impact ================================= fetchmail's SMTP client, when configured to authenticate [1], is susceptible to a protocol violation where, when a trusted but malicious or malfunctioning SMTP server responds to an authentication request with a "334" code but without a following blank on the line, it will attempt to start reading from memory address 0x1 to parse the server's SASL challenge. This address is constant and not under the attacker's control. This event will usually cause a crash of fetchmail. If fetchmail in this situation was running in daemon mode, this mode is also terminated by the crash. [1] This requires the esmtpname and esmtppassword options to be configured in the configuration file and the plugout and mda options to be inactive. As a word of warning, this vulnerability has eluded several static code analyzers. 3. Solutions ============ General recommendation: if running fetchmail in the background or in daemon mode, ensure that the daemon is supervised and crashes are reported so that action can be taken about the malfunctioning SMTP server, or on fetchmail's end to replace local delivery by different server or other means. 3a. Install fetchmail 6.5.6 or newer. The fetchmail source code is available from <https://sourceforge.net/projects/fetchmail/files/> and <https://gitlab.com/fetchmail/fetchmail/-/releases> The Git-based source code repository is currently published via https://gitlab.com/fetchmail/fetchmail/-/tree/legacy_6x (primary) https://sourceforge.net/p/fetchmail/git/ci/legacy_6x/tree/ (copy) 3b. Apply the smtp.c patch from the URL below and rebuild fetchmail: <https://gitlab.com/fetchmail/fetchmail/-/commit/4c3cebfa4e659fb778ca2cae0ccb3f69201609a8>
comment:4 by , 12 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at b637af31ef9b3dfff64a87f3b39ee645fb13a1b4
SA-12.4-017 issued
Note:
See TracTickets
for help on using tickets.

Fixes CVE-2025-61962.
https://www.fetchmail.info/fetchmail-SA-2025-01.txt