[ GLSA 202209-14 ] Fetchmail: Multiple Vulnerabilities

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <166411296132.9.6924835087017060442@90bb6a0775af>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202209-14
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: Low
    Title: Fetchmail: Multiple Vulnerabilities
     Date: September 25, 2022
     Bugs: #810676, #804921
       ID: 202209-14

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been discovered in Fetchmail, the worst of
which could result in email disclosure to third parties.

Background
==========

Fetchmail is a remote mail retrieval and forwarding utility.

Affected packages
=================

    -------------------------------------------------------------------
     Package              /     Vulnerable     /            Unaffected
    -------------------------------------------------------------------
  1  net-mail/fetchmail         < 6.4.22                    >= 6.4.22

Description
===========

Multiple vulnerabilities have been discovered in Fetchmail. Please
review the CVE identifiers referenced below for details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All Fetchmail users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=net-mail/fetchmail-6.4.22"

References
==========

[ 1 ] CVE-2021-36386
      https://nvd.nist.gov/vuln/detail/CVE-2021-36386
[ 2 ] CVE-2021-39272
      https://nvd.nist.gov/vuln/detail/CVE-2021-39272

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202209-14

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2022 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmMwWUEACgkQFMQkOaVy
+9lEkg/+NDtOeffwIvG2c+whfCjaWEA/4Ly657vX1X1FMfdFuDWYa9uFIZnVAuF+
C1NTq7oeusPPtIfZ8jGc6O27fSOvB3jiVDEefLRRioq6PphkNvX772lF1M9kjbEj
5zXQd6iy4vmGjHbdg5KDF53DH41+k50iVTMeFMHpkgE/MUbipx2QZeDUq2qlXs4D
GGjdYqnzh1Mf4sLW6raHVCvUhfI/otOFHvCP4RqNzF9hKZTOhZvQfUUyhjWGf/xU
p5+ynfKFTBCkFdzGwdc6sShpSvJojXSigZprpF0hhbLVdiYXg3QpjhYk4xK8VqX9
D0di3GwL+kv2QTHcWPJmWfJw+v7G3SFWtc9qgNy4pc6ICwOBUZAIKYN3ZDx9GRa0
ixrDMel8mPv1NyDqDSXjmuVBEg05rAixb1lD89drarE51/QyoXzvBgK7t3kgq8wG
1rxi2hwiIajPgGzXLS2hgMGu57P3MRRp/VsT4J9FjNcaHfdS6OFv2IxE+AkE72XA
LO7gRDtwkebJPagymP4t3FudFqDoEcsKlwqM8LG9UdEBL/in3wzi7s5GdJEpTKII
Xp49aBktgOtB8lXv3UtcuOYnnXY4+6hBcSuTBvnOZ5oqHhEhnfg4GtpP/YetSXoa
b19WCOoE0/URo/795+KfG0/9+bmemVolmQib4HjdErSyQWPOLWY=
=pQ8U
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.