ANNOUNCE: fetchmail 6.4.22 release candidate available (security and crash fixes)

Matthias Andree <[email protected]> Fri, 27 Aug 2021 20:02:21 +0200
Newsgroups gmane.mail.fetchmail.announce
Message-ID <YSkorcUipXwh+QDQ__20904.2369782523$1630087380$gmane$org@ryzen.an3e.de>
--===============0040154384344965442==
Content-Type: multipart/signed; micalg=pgp-sha512;
	protocol="application/pgp-signature"; boundary="YSjYVkepl+HlDOTN"
Content-Disposition: inline


--YSjYVkepl+HlDOTN
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Greetings,

The 6.4.22 release CANDIDATE #2 of fetchmail is now available at
<https://sourceforge.net/projects/fetchmail/files/branch_6.4/>.

It contains security fixes for CVE-2021-39272 and fixes up several protocol
violations along the way, fixes some configuration-based crashes (SIGSEGV) =
and
updates the documentation.

This version has quite extensive changes for a patchlevel release.

rc2 fixes an IMAP protocol regression of rc1 that made it unable to=20
download e-mail via IMAP in many circumstances.

Note that security recommendations in README.SSL were changed to achieve hi=
gher
security from the configuration. Built-in defaults do not change.

Please test this thoroughly and report your findings so we can be sure that
6.4.22 will be a good release.  It has been mailed out to the translation
project to solicit translation updates.

The source archive is available at:
<https://sourceforge.net/projects/fetchmail/files/branch_6.4/fetchmail-6.4.=
22.rc2.tar.xz/download>

Detached GnuPG signatures for the respective tarballs are at:
<https://sourceforge.net/projects/fetchmail/files/branch_6.4/fetchmail-6.4.=
22.rc2.tar.xz.asc/download>

SHA256 hash values for the tarballs:
SHA256(fetchmail-6.4.22.rc2.tar.xz)=3D 1bd3f25e221ea01de4ba57447b7464f8c5f0=
7f0f107701583b9cdd85740da276


Here are the release notes:

---------------------------------------------------------------------------=
------
fetchmail-6.4.22 (not yet released):

# SECURITY FIXES:
* On IMAP connections, without --ssl and with nonempty --sslproto, meaning =
that=20
  fetchmail is to enforce TLS, and when the server or an attacker sends=20
  a PREAUTH greeting, fetchmail used to continue an unencrypted connection.
  Now, log the error and abort the connection.
    Recommendation for servers that support SSL/TLS-wrapped or "implicit" m=
ode on
  a dedicated port (default 993): use --ssl, or the ssl user option in an r=
cfile.
    Reported by: Andrew C. Aitchison, based on the USENIX Security 21 paper=
 "Why=20
  TLS is better without STARTTLS - A Security Analysis of STARTTLS in the E=
mail=20
  Context" by Damian Poddebniak, Fabian Ising, Hanno B=F6ck, and Sebastian=
=20
  Schinzel.  The paper did not mention fetchmail.
* On IMAP and POP3 connections, --auth ssh no longer prevents STARTTLS=20
  negotiation.
* On IMAP connections, fetchmail does not permit overriding a server-side=
=20
  LOGINDISABLED with --auth password any more.
* On POP3 connections, the possibility for RPA authentication (by probing w=
ith=20
  an AUTH command without arguments) no longer prevents STARTTLS negotiatio=
n.
* For POP3 connections, only attempt RPA if the authentication type is "any=
".

# BUG FIXES:
* On IMAP connections, when AUTHENTICATE EXTERNAL fails and we have receive=
d the=20
  tagged (=3D final) response, do not send "*".
* On IMAP connections, AUTHENTICATE EXTERNAL without username will properly=
 send=20
  a "=3D" for protocol compliance.
* On IMAP connections, AUTHENTICATE EXTERNAL will now check if the server=
=20
  advertised SASL-IR (RFC-4959) support and otherwise refuse (fetchmail <=
=3D 6.4=20
  has not supported and does not support the separate challenge/response wi=
th=20
  command continuation)
* On IMAP connections, when --auth external is requested but not advertised=
 by=20
  the server, log a proper error message.
* Fetchmail no longer crashes when attempting a connection with --plugin ""=
 or=20
  --plugout "".
* Fetchmail no longer leaks memory when processing the arguments of --plugi=
n or=20
  --plugout on connections.
* On POP3 connections, the CAPAbilities parser is now caseblind.
* Fix segfault on configurations with "defaults ... no envelope". Reported =
by =20
  Bj=F8rn Mork. Fixes Debian Bug#992400.  This is a regression in fetchmail=
 6.4.3
  and happened when plugging memory leaks, which did not account for that t=
he=20
  envelope parameter is special when set as "no envelope". The segfault hap=
pens
  in a constant strlen(-1), triggered by trusted local input =3D> no vulner=
ability.

# CHANGES:
* IMAP: When fetchmail is in not-authenticated state and the server volunte=
ers=20
  CAPABILITY information, use it and do not re-probe. (After STARTTLS, fetc=
hmail=20
  must and will re-probe explicitly.)
* For typical POP3/IMAP ports 110, 143, 993, 995, if port and --ssl option
  do not match, emit a warning and continue. Closes Gitlab #31.
  (cherry-picked from 6.5 beta branch "legacy_6x")
* fetchmail.man and README.SSL were updated in line with RFC-8314/8996/8997
  recommendations to prefer Implicit TLS (--ssl/ssl) and TLS v1.2 or newer,
  placing --sslproto tls1.2+ more prominently.
  The defaults shall not change between 6.4.X releases for compatibility.

# TRANSLATIONS: These language translations were updated by these fine peop=
le:
* fr:    Fr=E9d=E9ric Marchal [French]
* eo:    Keith Bowes [Esperanto]

---------------------------------------------------------------------------=
-----

Happy fetches,
Matthias

--YSjYVkepl+HlDOTN
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE3EplW9mTzUhx+oIQ5BKxVu/zhVoFAmEpKK0ACgkQ5BKxVu/z
hVpfQQ/+KM5hVBp+fzjdgbGEYylKl6iKcQ4PA02mijghh9gJoufHYSla6cpCH5Oe
ZgJ8vBdv27/pt2XfABRiKD7C+8uQ1clPjCclNOGSlcNWunXB2CTxpEGgu2phaUJA
vk+TzCfxqzCGoVWV9I8MACXScawTbzSliMqG2V0LTe5fbi16bt03a2/B0M/1BWOE
bnRvAeJh8T1ovzuGrsByrQGyJEkW8ymNpZryjbAEOwIy/RfVYkD9R+Pm4iaOnst9
pATwNA7dxm1rejv8uH2KTD+XxIk23iUJbSzEtqdV25PNq884stSW9JYEiHXDO+Ep
wfnUQcFdqg1Ia1ZE3VgHQqTfh9lA3dK/xC+pWhWjK/wBTLSMjDaTnk6WGyTj998/
Lf7H25+cE+A//ZVZCKAwaNokGrmI3m3JOgr1TCxf4cmYpGPZEXv7D3c5cgu3i4Nu
MbqMsnVSCicM4CE0MCQ5TnxOSgtEmBXXT6OvSvr/gtT4Jnfqlbf1PkklUR7B46yn
+yaSzmReRo/ISFo9hoesaC3OP43M43vRFqy2TVQ+rlKPwO+Rj8mHxoS5iMsV49J9
tXHBXJyXsNXxhadRyztjo2RGsSfon/T3dAfqZC2aZmL9bVxHThYBuXVuufMsvGrv
SqcUGhbRGBG9TtR8f738bix/VmIh1iUMfddc77RyxyGyCqSvMZk=
=YADY
-----END PGP SIGNATURE-----

--YSjYVkepl+HlDOTN--


--===============0040154384344965442==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============0040154384344965442==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Fetchmail-announce mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/fetchmail-announce

--===============0040154384344965442==--