Input validation error in Fetchmail - CVE-2025-61962
Published: October 20, 2025
Vulnerability identifier: #VU117379
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-61962
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input during authentication. A remote attacker that controls SMTP server can send 334 status code response and crash the mail client.
Affected software
Fetchmail
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Desktop Applications Module
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Fedora
fetchmailconf
fetchmail-debugsource
fetchmail
fetchmail-debuginfo
fetchmail-help
fetchmail (Ubuntu package)
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Desktop Applications Module
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Fedora
fetchmailconf
fetchmail-debugsource
fetchmail
fetchmail-debuginfo
fetchmail-help
fetchmail (Ubuntu package)
How to mitigate CVE-2025-61962
Install updates from vendor's website.
Fetchmail - update to 6.5.6
fetchmailconf - addressed in versions 6.3.26-13.21.1, 6.4.22-150600.35.3.1
fetchmail-debugsource - addressed in versions 6.3.26-13.21.1, 6.4.22-150600.35.3.1
fetchmail - addressed in versions 6.3.26-13.21.1, 6.4.22-150600.35.3.1
fetchmail-debuginfo - addressed in versions 6.3.26-13.21.1, 6.4.22-150600.35.3.1
fetchmail-help - update to 6.4.22-2
fetchmail-debugsource - addressed in versions 6.4.22-2, 6.4.22-3, 6.4.37-2
fetchmail-debuginfo - addressed in versions 6.4.22-2, 6.4.22-3, 6.4.37-2
fetchmail - addressed in versions 6.4.22-2, 6.4.22-3, 6.4.37-2
fetchmail (Ubuntu package) - addressed in versions 6.4.27-1ubuntu0.1, 6.4.38-1ubuntu4.1, 6.4.39-1ubuntu0.1
fetchmail - addressed in versions 6.5.6-1.fc41, 6.5.6-1.fc42, 6.5.6-1.fc43
fetchmailconf - addressed in versions 6.3.26-13.21.1, 6.4.22-150600.35.3.1
fetchmail-debugsource - addressed in versions 6.3.26-13.21.1, 6.4.22-150600.35.3.1
fetchmail - addressed in versions 6.3.26-13.21.1, 6.4.22-150600.35.3.1
fetchmail-debuginfo - addressed in versions 6.3.26-13.21.1, 6.4.22-150600.35.3.1
fetchmail-help - update to 6.4.22-2
fetchmail-debugsource - addressed in versions 6.4.22-2, 6.4.22-3, 6.4.37-2
fetchmail-debuginfo - addressed in versions 6.4.22-2, 6.4.22-3, 6.4.37-2
fetchmail - addressed in versions 6.4.22-2, 6.4.22-3, 6.4.37-2
fetchmail (Ubuntu package) - addressed in versions 6.4.27-1ubuntu0.1, 6.4.38-1ubuntu4.1, 6.4.39-1ubuntu0.1
fetchmail - addressed in versions 6.5.6-1.fc41, 6.5.6-1.fc42, 6.5.6-1.fc43
External References
Related Security Bulletins
- Denial of service in Fetchmail
- Fedora 43 update for fetchmail
- Fedora 42 update for fetchmail
- Fedora 41 update for fetchmail
- openEuler 24.03 LTS SP2 update for fetchmail
- openEuler 24.03 LTS SP1 update for fetchmail
- openEuler 24.03 LTS update for fetchmail
- openEuler 22.03 LTS SP4 update for fetchmail
- openEuler 22.03 LTS SP3 update for fetchmail
- openEuler 20.03 LTS SP4 update for fetchmail
- Ubuntu update for fetchmail
- SUSE update for fetchmail
- SUSE update for fetchmail