ANNOUNCE: The 6.4.22 release of fetchmail is available (security fixes for CVE-2021-39272, crash fixes, other changes)

Matthias Andree <[email protected]> Mon, 13 Sep 2021 23:06:06 +0200
Newsgroups gmane.mail.fetchmail.announce
Message-ID <YT+9PsDtVSAdOP7x__5441.07410112105$1631567216$gmane$org@ryzen.an3e.de>
--===============6260626188860331516==
Content-Type: multipart/signed; micalg=pgp-sha512;
	protocol="application/pgp-signature"; boundary="ehubHNofIAeNfclZ"
Content-Disposition: inline


--ehubHNofIAeNfclZ
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Greetings,

The 6.4.22 release of fetchmail is now available at=20
<https://sourceforge.net/projects/fetchmail/files/branch_6.4/>.

It contains the security fix for CVE-2021-39272 of 6.4.21 and earlier,
fixes some crashes that can be triggered by local configurations,
and makes some fixes to authentication and other changes, details below.

DISTRIBUTORS please note OpenSSL's licensing change for OpenSSL 3,
and you may want to review COPYING.

The source archive is available at:
<https://sourceforge.net/projects/fetchmail/files/branch_6.4/fetchmail-6.4.=
22.tar.xz/download>
<https://sourceforge.net/projects/fetchmail/files/branch_6.4/fetchmail-6.4.=
22.tar.lz/download>

Detached GnuPG signatures for the respective tarballs are at:
<https://sourceforge.net/projects/fetchmail/files/branch_6.4/fetchmail-6.4.=
22.tar.xz.asc/download>
<https://sourceforge.net/projects/fetchmail/files/branch_6.4/fetchmail-6.4.=
22.tar.lz.asc/download>

SHA256 hash values for the tarballs:
SHA256(fetchmail-6.4.22.tar.lz)=3D 5e596136660cca9b71f73c0f6fe79cc76db7db2b=
2dc33c08ad25241ed0cba368
SHA256(fetchmail-6.4.22.tar.xz)=3D 104379499a1346330a6799f1e20c790211dd0783=
5cb1af5668dfd25de71357f4

Here are the release notes:

---------------------------------------------------------------------------=
------
fetchmail-6.4.22 (released 2021-09-13, 30201 LoC):

# OPENSSL AND LICENSING NOTE:
* fetchmail 6.4.22 is compatible with OpenSSL 1.1.1 and 3.0.0.
  OpenSSL's licensing changed between these releases from dual OpenSSL/SSLe=
ay=20
  license to Apache License v2.0, which is considered incompatible with GPL=
 v2=20
  by the FSF.  For implications and details, see the file COPYING.

# SECURITY FIXES:
* CVE-2021-39272: fetchmail-SA-2021-02: On IMAP connections, without --ssl =
and=20
  with nonempty --sslproto, meaning that fetchmail is to enforce TLS, and w=
hen=20
  the server or an attacker sends a PREAUTH greeting, fetchmail used to con=
tinue=20
  an unencrypted connection.  Now, log the error and abort the connection.
  --Recommendation for servers that support SSL/TLS-wrapped or "implicit" m=
ode on
  a dedicated port (default 993): use --ssl, or the ssl user option in an r=
cfile.
  --Reported by: Andrew C. Aitchison, based on the USENIX Security 21 paper=
 "Why=20
  TLS is better without STARTTLS - A Security Analysis of STARTTLS in the E=
mail=20
  Context" by Damian Poddebniak, Fabian Ising, Hanno B=F6ck, and Sebastian=
=20
  Schinzel.  The paper did not mention fetchmail.

* On IMAP and POP3 connections, --auth ssh no longer prevents STARTTLS=20
  negotiation.
* On IMAP connections, fetchmail does not permit overriding a server-side=
=20
  LOGINDISABLED with --auth password any more.
* On POP3 connections, the possibility for RPA authentication (by probing w=
ith=20
  an AUTH command without arguments) no longer prevents STARTTLS negotiatio=
n.
* For POP3 connections, only attempt RPA if the authentication type is "any=
".

# BUG FIXES:
* On IMAP connections, when AUTHENTICATE EXTERNAL fails and we have receive=
d the=20
  tagged (=3D final) response, do not send "*".
* On IMAP connections, AUTHENTICATE EXTERNAL without username will properly=
 send=20
  a "=3D" for protocol compliance.
* On IMAP connections, AUTHENTICATE EXTERNAL will now check if the server=
=20
  advertised SASL-IR (RFC-4959) support and otherwise refuse (fetchmail <=
=3D 6.4=20
  has not supported and does not support the separate challenge/response wi=
th=20
  command continuation)
* On IMAP connections, when --auth external is requested but not advertised=
 by=20
  the server, log a proper error message.
* Fetchmail no longer crashes when attempting a connection with --plugin ""=
 or=20
  --plugout "".
* Fetchmail no longer leaks memory when processing the arguments of --plugi=
n or=20
  --plugout on connections.
* On POP3 connections, the CAPAbilities parser is now caseblind.
* Fix segfault on configurations with "defaults ... no envelope". Reported =
by =20
  Bj=F8rn Mork. Fixes Debian Bug#992400.  This is a regression in fetchmail=
 6.4.3
  and happened when plugging memory leaks, which did not account for that t=
he=20
  envelope parameter is special when set as "no envelope". The segfault hap=
pens
  in a constant strlen(-1), triggered by trusted local input =3D> no vulner=
ability.
* Fix program abort (SIGABRT) with "internal error" when invalid sslproto i=
s=20
  given with OpenSSL 1.1.0 API compatible SSL implementations.

# CHANGES:
* IMAP: When fetchmail is in not-authenticated state and the server volunte=
ers=20
  CAPABILITY information, use it and do not re-probe. (After STARTTLS, fetc=
hmail=20
  must and will re-probe explicitly.)
* For typical POP3/IMAP ports 110, 143, 993, 995, if port and --ssl option
  do not match, emit a warning and continue. Closes Gitlab #31.
  (cherry-picked from 6.5 beta branch "legacy_6x")
* fetchmail.man and README.SSL were updated in line with RFC-8314/8996/8997
  recommendations to prefer Implicit TLS (--ssl/ssl) and TLS v1.2 or newer,
  placing --sslproto tls1.2+ more prominently.
  The defaults shall not change between 6.4.X releases for compatibility.

# TRANSLATIONS: language translations were updated by these fine people:
* sq:    Besnik Bleta [Albanian]
* cs:    Petr Pisar [Czech]
* eo:    Keith Bowes [Esperanto]
* fr:    Fr=E9d=E9ric Marchal [French]
* pl:    Jakub Bogusz [Polish]
* sv:    G=F6ran Uddeborg [Swedish]

# CREDITS:
* Thanks for testing the release candidates and bug reports to:
  Corey Halpin, Stefan E=DFer.

---------------------------------------------------------------------------=
-----

Happy fetches,
Matthias

--ehubHNofIAeNfclZ
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE3EplW9mTzUhx+oIQ5BKxVu/zhVoFAmE/vT0ACgkQ5BKxVu/z
hVqrQA/9GcXL06wxJE1tO976svMCjYjKjLD/1srh9isBdgEhXSScb72Jx1XUXXR5
v/PT/24As82GEhRXw5StvZeKcaXfW7WRnMQnN62R4R8BF6W45WXpy3rRPAN8ln3t
muCroy4VoiAcTH1lsRZvc/+DjbxQWzSBJj3AywBPTwcGW8utSPXDHvFoHOdSEaPF
XtoNNs2Z0AM+3ZX8rlo5z4lYXraYVYfPcqs/WbffSZsP/tVd6levoDY05MgBsr6p
iwnqo75lGa18NVNo4Q6LAVsm58Cvf4/41peON1XstchDRq02PpG8+dfC8Jv4U6t0
31RheR2natbIfew1uvTIG6+4NgkAnNOZYXfwjmqSeLLTicBH2xt7V0CVwCotw3O2
e5yyat9oOq+STwUlu1+sj7umV4v0p8o0d3t5F+muRiCWf6rOzKqvc7HtjD0e6LjP
/RflRJYNxGg9v8LdBCTpxWjtqLBRUdVfoTaWBispgFmnR74Kyz94cwGSp1/9s/aU
1KACG3EjERdLwjOsScv+DVgWkkbpxYKRS1eiGrFY4GHI2OiY0CmlzzNSi2LqVMIR
cL5j7ahc3zMLqtySXZxTSkEAPApWE3oZLFAK6B5GbqzNDprf5lfkWLgqqV0VuAKa
StEV3QMYc3UUJm6AlikUnqUdnk37GnPu0aMbhbyxTqWABAcPDQ4=
=FG87
-----END PGP SIGNATURE-----

--ehubHNofIAeNfclZ--


--===============6260626188860331516==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============6260626188860331516==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Fetchmail-announce mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/fetchmail-announce

--===============6260626188860331516==--