<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:01:50 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:1964 — Moderate: fetchmail security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:1964</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: fetchmail&lt;/p&gt;
&lt;p&gt;Fetchmail is a remote mail retrieval and forwarding utility intended for use over on-demand TCP/IP links, like SLIP or PPP connections. Fetchmail supports every remote-mail protocol currently in use on the Internet (POP2, POP3, RPOP, APOP, KPOP, all IMAPs, ESMTP ETRN, IPv6, and IPSEC) for retrieval. Then Fetchmail forwards the mail through SMTP so the user can read it through their favorite mail client.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* fetchmail: DoS or information disclosure when logging long messages (CVE-2021-36386)&lt;/p&gt;
&lt;p&gt;* fetchmail: STARTTLS session encryption bypassing (CVE-2021-39272)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: fetchmail&lt;/p&gt;
&lt;p&gt;Fetchmail is a remote mail retrieval and forwarding utility intended for use over on-demand TCP/IP links, like SLIP or PPP connections. Fetchmail supports every remote-mail protocol currently in use on the Internet (POP2, POP3, RPOP, APOP, KPOP, all IMAPs, ESMTP ETRN, IPv6, and IPSEC) for retrieval. Then Fetchmail forwards the mail through SMTP so the user can read it through their favorite mail client.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* fetchmail: DoS or information disclosure when logging long messages (CVE-2021-36386)&lt;/p&gt;
&lt;p&gt;* fetchmail: STARTTLS session encryption bypassing (CVE-2021-39272)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:1964</guid>
    </item>
    <item>
      <title>CLEANSTART-2024-QK25555 — Fetchmail before 6</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2024-qk25555</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: fetchmail&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the fetchmail package. Fetchmail before 6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: fetchmail&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the fetchmail package. Fetchmail before 6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2024-qk25555</guid>
    </item>
    <item>
      <title>EUVD-2026-30558</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-30558</link>
      <description>EUVD-2026-30558</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-30558</guid>
    </item>
    <item>
      <title>fkie_cve-2021-39272</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-39272</link>
      <description>&lt;p&gt;Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-39272</guid>
    </item>
    <item>
      <title>GHSA-x8j8-pwr7-frjw</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x8j8-pwr7-frjw</link>
      <description>&lt;p&gt;Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x8j8-pwr7-frjw</guid>
    </item>
    <item>
      <title>gsd-2021-39272</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-39272</link>
      <description>gsd-2021-39272</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-39272</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-39272 — Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances such as a certain situation…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-39272</link>
      <description>msrc_CVE-2021-39272</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-39272</guid>
    </item>
    <item>
      <title>OESA-2021-1360 — fetchmail security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1360</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: fetchmail, openEuler:20.03-LTS-SP2: fetchmail&lt;/p&gt;
&lt;p&gt;Fetchmail is a remote mail retrieval and forwarding utility intended for use over on-demand TCP/IP links, like SLIP or PPP connections. Fetchmail supports every remote-mail protocol currently in use on the Internet (POP2, POP3, RPOP, APOP, KPOP, all IMAPs, ESMTP ETRN, IPv6, and IPSEC) for retrieval. Then Fetchmail forwards the mail through SMTP so you can read it through your favorite mail client. Install fetchmail if you need to retrieve mail over SLIP or PPP connections.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.(CVE-2021-39272)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: fetchmail, openEuler:20.03-LTS-SP2: fetchmail&lt;/p&gt;
&lt;p&gt;Fetchmail is a remote mail retrieval and forwarding utility intended for use over on-demand TCP/IP links, like SLIP or PPP connections. Fetchmail supports every remote-mail protocol currently in use on the Internet (POP2, POP3, RPOP, APOP, KPOP, all IMAPs, ESMTP ETRN, IPv6, and IPSEC) for retrieval. Then Fetchmail forwards the mail through SMTP so you can read it through your favorite mail client. Install fetchmail if you need to retrieve mail over SLIP or PPP connections.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.(CVE-2021-39272)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1360</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:1416-1 — Security update for fetchmail</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:1416-1</link>
      <description>&lt;p&gt;Security update for fetchmail&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for fetchmail&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:1416-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:3492-1 — Security update for fetchmail</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:3492-1</link>
      <description>&lt;p&gt;Security update for fetchmail&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for fetchmail&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:3492-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-39272</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-39272</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: fetchmail, Ubuntu:18.04:LTS: fetchmail, Ubuntu:20.04:LTS: fetchmail&lt;/p&gt;
&lt;p&gt;Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: fetchmail, Ubuntu:18.04:LTS: fetchmail, Ubuntu:20.04:LTS: fetchmail&lt;/p&gt;
&lt;p&gt;Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-39272</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0302 — Xerox FreeFlow Print Server: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode mit Administrator…</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0302</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0302</guid>
    </item>
  </channel>
</rss>
