SB2021102120 - MitM attack in Fetchmail
Published: October 21, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Inadequate Encryption Strength (CVE-ID: CVE-2021-39272)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in
some circumstances, such as a certain situation with IMAP and PREAUTH. A remote attacker with ability to intercept network traffic can gain access to sensitive information.
Remediation
Install update from vendor's website.
References
- https://nostarttls.secvuln.info/
- http://www.openwall.com/lists/oss-security/2021/08/27/3
- https://www.fetchmail.info/security.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L3XJ6XLEJCEZCAM5LGGD6XBCC522QLG4/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZYCYLL73NP7ALJWSDICIVSA47ZIXWSSA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VXMKSEHAQSEDCWZMAOJEGX3P3JW6QY6H/