ANNOUNCE: The 6.4.20 release of fetchmail is available (security update CVE-2021-36386)

Matthias Andree <[email protected]> Wed, 28 Jul 2021 23:04:02 +0200
Newsgroups gmane.mail.fetchmail.announce
Message-ID <YQHGQu5jg1lSHsfP__9838.58788838319$1627506286$gmane$org@ryzen.an3e.de>
--===============2946581260338065494==
Content-Type: multipart/signed; micalg=pgp-sha512;
	protocol="application/pgp-signature"; boundary="tSKRCqENT7zewVwV"
Content-Disposition: inline


--tSKRCqENT7zewVwV
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Greetings,

The 6.4.20 release of fetchmail is now available at the usual locations,
including <https://sourceforge.net/projects/fetchmail/files/branch_6.4/>.

It contains an LMTP bug fix, updates fetchmailconf and the Serbian=20
translation.

The source archive is available at:
<https://sourceforge.net/projects/fetchmail/files/branch_6.4/fetchmail-6.4.=
20.tar.xz/download>
<https://sourceforge.net/projects/fetchmail/files/branch_6.4/fetchmail-6.4.=
20.tar.lz/download>

Detached GnuPG signatures for the respective tarballs are at:
<https://sourceforge.net/projects/fetchmail/files/branch_6.4/fetchmail-6.4.=
20.tar.xz.asc/download>
<https://sourceforge.net/projects/fetchmail/files/branch_6.4/fetchmail-6.4.=
20.tar.lz.asc/download>

SHA256 hash values for the tarballs:
SHA256(fetchmail-6.4.20.tar.lz)=3D 497973353c0538216e7d7f2289a21d9acc5edd78=
f06d7ec008001f4f19e91b11
SHA256(fetchmail-6.4.20.tar.xz)=3D c82141ae2e8f0039ceb0c5c2eda43c5e93ad0bf7=
f9c6bb628092b3be74386176

Here are the release notes:

---------------------------------------------------------------------------=
------
fetchmail-6.4.20 (released 2021-07-28, 30042 LoC):

# SECURITY FIX:
* When a log message exceeds c. 2 kByte in size, for instance, with very lo=
ng=20
  header contents, and depending on verbosity option, fetchmail can crash or
  misreport each first log message that requires a buffer reallocation.
  fetchmail then reallocates memory and re-runs vsnprintf() without another=
=20
  call to va_start(), so it reads garbage. The exact impact depends on=20
  many factors around the compiler and operating system configurations used=
 and=20
  the implementation details of the stdarg.h interfaces of the two functions
  mentioned before. To fix CVE-2021-38386.

  Reported by Christian Herdtweck of Intra2net AG, T=FCbingen, Germany.
---------------------------------------------------------------------------=
------

Happy fetches,
Matthias

--tSKRCqENT7zewVwV
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE3EplW9mTzUhx+oIQ5BKxVu/zhVoFAmEBxkIACgkQ5BKxVu/z
hVpssw/9G8GEA0NiBP45a4b+jRlxX2ruspFpqWb+ymfz6FJOmETOoHqNo0E8lYGP
ESLRvv3XIjQMt5V8NqGgMcF4J2DUgHWZqjwMCsNZzzU5kIJoId0hhmh3sWSYgpB0
6Qwd6Ay1QWOTj6Dqyqh52kj1RcH4MKRYmmxhsYJLz6ZP5swLMMyV6eI6y4KiELmv
EHKic3hT05NmgeUC2v9F65gdkI15gD+M/DzKDPhKj9z7ibASTLfkEpopX54Dtc5S
iYrgi5LVA8LA33tj62NjPnon8TT3S5wlgILMf8t578Yy8O56AJOo3v84vkhNyTGz
i0hGRiQdecicvbfx0DrSjlAVdWNjqKcBPV0i/PrsF8tqOUITCJgn9+ZsVOLRj8vQ
fXMwN4mkbGl6glJ4p5s8eODAHwnwmBP8H1xQ8QTr7UYlawYGhNGivm/5V0WzjxVO
0JK/zgf4NpfPxrkmMcOGvc21RPv0e6hfDwLiesmVR8M0qKdFaNG+lwbFjHf4TGVe
YXibvSvkIJtNjAjI6dTI7nCVVNR5pvXBcuUKwzSo0ahdnXDzKh6HxqU/riZKMjNG
HCA3SXe3NLTY5H+0H9LvnJZHygBsBIgRFESCxedpjuw7CacFMLmh7iyW0m4Qx749
Nz9eHqgrptNIeRyj3ubJ4zvzw0R6FxcZhMB1ufc76EoiFETPWy8=
=IvG2
-----END PGP SIGNATURE-----

--tSKRCqENT7zewVwV--


--===============2946581260338065494==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============2946581260338065494==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Fetchmail-announce mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/fetchmail-announce

--===============2946581260338065494==--