<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:22:49 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:1964 — Moderate: fetchmail security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:1964</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: fetchmail&lt;/p&gt;
&lt;p&gt;Fetchmail is a remote mail retrieval and forwarding utility intended for use over on-demand TCP/IP links, like SLIP or PPP connections. Fetchmail supports every remote-mail protocol currently in use on the Internet (POP2, POP3, RPOP, APOP, KPOP, all IMAPs, ESMTP ETRN, IPv6, and IPSEC) for retrieval. Then Fetchmail forwards the mail through SMTP so the user can read it through their favorite mail client.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* fetchmail: DoS or information disclosure when logging long messages (CVE-2021-36386)&lt;/p&gt;
&lt;p&gt;* fetchmail: STARTTLS session encryption bypassing (CVE-2021-39272)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: fetchmail&lt;/p&gt;
&lt;p&gt;Fetchmail is a remote mail retrieval and forwarding utility intended for use over on-demand TCP/IP links, like SLIP or PPP connections. Fetchmail supports every remote-mail protocol currently in use on the Internet (POP2, POP3, RPOP, APOP, KPOP, all IMAPs, ESMTP ETRN, IPv6, and IPSEC) for retrieval. Then Fetchmail forwards the mail through SMTP so the user can read it through their favorite mail client.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* fetchmail: DoS or information disclosure when logging long messages (CVE-2021-36386)&lt;/p&gt;
&lt;p&gt;* fetchmail: STARTTLS session encryption bypassing (CVE-2021-39272)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:1964</guid>
    </item>
    <item>
      <title>bdu:2021-03928</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-03928</link>
      <description>bdu:2021-03928</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-03928</guid>
    </item>
    <item>
      <title>CLEANSTART-2024-YI47904 — report_vbuild in report</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2024-yi47904</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: fetchmail&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the fetchmail package. report_vbuild in report.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: fetchmail&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the fetchmail package. report_vbuild in report.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2024-yi47904</guid>
    </item>
    <item>
      <title>EUVD-2026-29372</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-29372</link>
      <description>EUVD-2026-29372</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-29372</guid>
    </item>
    <item>
      <title>fkie_cve-2021-36386</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-36386</link>
      <description>&lt;p&gt;report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-36386</guid>
    </item>
    <item>
      <title>GHSA-rr6c-95pp-cpgf</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rr6c-95pp-cpgf</link>
      <description>&lt;p&gt;report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rr6c-95pp-cpgf</guid>
    </item>
    <item>
      <title>gsd-2021-36386</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-36386</link>
      <description>gsd-2021-36386</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-36386</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-36386 — report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument w…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-36386</link>
      <description>msrc_CVE-2021-36386</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-36386</guid>
    </item>
    <item>
      <title>OESA-2021-1314 — fetchmail security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1314</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: fetchmail, openEuler:20.03-LTS-SP2: fetchmail&lt;/p&gt;
&lt;p&gt;Fetchmail is a remote mail retrieval and forwarding utility intended for use over on-demand TCP/IP links, like SLIP or PPP connections. Fetchmail supports every remote-mail protocol currently in use on the Internet (POP2, POP3, RPOP, APOP, KPOP, all IMAPs, ESMTP ETRN, IPv6, and IPSEC) for retrieval. Then Fetchmail forwards the mail through SMTP so you can read it through your favorite mail client. Install fetchmail if you need to retrieve mail over SLIP or PPP connections.&#13;
&#13;
Security Fix(es):&#13;
&#13;
report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.(CVE-2021-36386)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: fetchmail, openEuler:20.03-LTS-SP2: fetchmail&lt;/p&gt;
&lt;p&gt;Fetchmail is a remote mail retrieval and forwarding utility intended for use over on-demand TCP/IP links, like SLIP or PPP connections. Fetchmail supports every remote-mail protocol currently in use on the Internet (POP2, POP3, RPOP, APOP, KPOP, all IMAPs, ESMTP ETRN, IPv6, and IPSEC) for retrieval. Then Fetchmail forwards the mail through SMTP so you can read it through your favorite mail client. Install fetchmail if you need to retrieve mail over SLIP or PPP connections.&#13;
&#13;
Security Fix(es):&#13;
&#13;
report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.(CVE-2021-36386)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1314</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:1183-1 — Security update for fetchmail</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:1183-1</link>
      <description>&lt;p&gt;Security update for fetchmail&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for fetchmail&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:1183-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:2771-1 — Security update for fetchmail</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:2771-1</link>
      <description>&lt;p&gt;Security update for fetchmail&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for fetchmail&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:2771-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-36386</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-36386</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: fetchmail, Ubuntu:18.04:LTS: fetchmail, Ubuntu:20.04:LTS: fetchmail&lt;/p&gt;
&lt;p&gt;report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: fetchmail, Ubuntu:18.04:LTS: fetchmail, Ubuntu:20.04:LTS: fetchmail&lt;/p&gt;
&lt;p&gt;report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-36386</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1525 — fetchmail: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1525</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in fetchmail ausnutzen, um einen Denial of Service Angriff durchzuführen oder Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in fetchmail ausnutzen, um einen Denial of Service Angriff durchzuführen oder Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1525</guid>
    </item>
  </channel>
</rss>
