Inadequate Encryption Strength in Fetchmail - CVE-2021-39272
Published: October 21, 2021
Fetchmail
fetchmail.berlios.de
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in
some circumstances, such as a certain situation with IMAP and PREAUTH. A remote attacker with ability to intercept network traffic can gain access to sensitive information.
Remediation
External links
- https://nostarttls.secvuln.info/
- http://www.openwall.com/lists/oss-security/2021/08/27/3
- https://www.fetchmail.info/security.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L3XJ6XLEJCEZCAM5LGGD6XBCC522QLG4/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZYCYLL73NP7ALJWSDICIVSA47ZIXWSSA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VXMKSEHAQSEDCWZMAOJEGX3P3JW6QY6H/