ANNOUNCE: The 6.4.20 release of fetchmail is available (security update CVE-2021-36386)
Matthias Andree <[email protected]> Wed, 28 Jul 2021 23:04:02 +0200
| Newsgroups | gmane.mail.fetchmail.announce |
|---|---|
| Message-ID | <YQHGQu5jg1lSHsfP__9838.58788838319$1627506286$gmane$org@ryzen.an3e.de> |
--===============2946581260338065494== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="tSKRCqENT7zewVwV" Content-Disposition: inline --tSKRCqENT7zewVwV Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Greetings, The 6.4.20 release of fetchmail is now available at the usual locations, including <https://sourceforge.net/projects/fetchmail/files/branch_6.4/>. It contains an LMTP bug fix, updates fetchmailconf and the Serbian=20 translation. The source archive is available at: <https://sourceforge.net/projects/fetchmail/files/branch_6.4/fetchmail-6.4.= 20.tar.xz/download> <https://sourceforge.net/projects/fetchmail/files/branch_6.4/fetchmail-6.4.= 20.tar.lz/download> Detached GnuPG signatures for the respective tarballs are at: <https://sourceforge.net/projects/fetchmail/files/branch_6.4/fetchmail-6.4.= 20.tar.xz.asc/download> <https://sourceforge.net/projects/fetchmail/files/branch_6.4/fetchmail-6.4.= 20.tar.lz.asc/download> SHA256 hash values for the tarballs: SHA256(fetchmail-6.4.20.tar.lz)=3D 497973353c0538216e7d7f2289a21d9acc5edd78= f06d7ec008001f4f19e91b11 SHA256(fetchmail-6.4.20.tar.xz)=3D c82141ae2e8f0039ceb0c5c2eda43c5e93ad0bf7= f9c6bb628092b3be74386176 Here are the release notes: ---------------------------------------------------------------------------= ------ fetchmail-6.4.20 (released 2021-07-28, 30042 LoC): # SECURITY FIX: * When a log message exceeds c. 2 kByte in size, for instance, with very lo= ng=20 header contents, and depending on verbosity option, fetchmail can crash or misreport each first log message that requires a buffer reallocation. fetchmail then reallocates memory and re-runs vsnprintf() without another= =20 call to va_start(), so it reads garbage. The exact impact depends on=20 many factors around the compiler and operating system configurations used= and=20 the implementation details of the stdarg.h interfaces of the two functions mentioned before. To fix CVE-2021-38386. Reported by Christian Herdtweck of Intra2net AG, T=FCbingen, Germany. ---------------------------------------------------------------------------= ------ Happy fetches, Matthias --tSKRCqENT7zewVwV Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE3EplW9mTzUhx+oIQ5BKxVu/zhVoFAmEBxkIACgkQ5BKxVu/z hVpssw/9G8GEA0NiBP45a4b+jRlxX2ruspFpqWb+ymfz6FJOmETOoHqNo0E8lYGP ESLRvv3XIjQMt5V8NqGgMcF4J2DUgHWZqjwMCsNZzzU5kIJoId0hhmh3sWSYgpB0 6Qwd6Ay1QWOTj6Dqyqh52kj1RcH4MKRYmmxhsYJLz6ZP5swLMMyV6eI6y4KiELmv EHKic3hT05NmgeUC2v9F65gdkI15gD+M/DzKDPhKj9z7ibASTLfkEpopX54Dtc5S iYrgi5LVA8LA33tj62NjPnon8TT3S5wlgILMf8t578Yy8O56AJOo3v84vkhNyTGz i0hGRiQdecicvbfx0DrSjlAVdWNjqKcBPV0i/PrsF8tqOUITCJgn9+ZsVOLRj8vQ fXMwN4mkbGl6glJ4p5s8eODAHwnwmBP8H1xQ8QTr7UYlawYGhNGivm/5V0WzjxVO 0JK/zgf4NpfPxrkmMcOGvc21RPv0e6hfDwLiesmVR8M0qKdFaNG+lwbFjHf4TGVe YXibvSvkIJtNjAjI6dTI7nCVVNR5pvXBcuUKwzSo0ahdnXDzKh6HxqU/riZKMjNG HCA3SXe3NLTY5H+0H9LvnJZHygBsBIgRFESCxedpjuw7CacFMLmh7iyW0m4Qx749 Nz9eHqgrptNIeRyj3ubJ4zvzw0R6FxcZhMB1ufc76EoiFETPWy8= =IvG2 -----END PGP SIGNATURE----- --tSKRCqENT7zewVwV-- --===============2946581260338065494== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============2946581260338065494== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Fetchmail-announce mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/fetchmail-announce --===============2946581260338065494==--