In fetchmail before 6.5.6, the SMTP client can crash when authenticating upon receiving a 334 status code in a malformed context.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade fetchmail | Dec 5, 2025 | Oct 4, 2025 |
| Amazon_linux_2023 | — | Upgrade fetchmail-debugsourceUpgrade fetchmailUpgrade fetchmail-debuginfo | Dec 9, 2025 | Oct 4, 2025 |
| Freebsd | — | Upgrade fetchmail | Dec 10, 2025 | Oct 3, 2025 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Oct 4, 2025 |
| Suse | — | Upgrade fetchmailconfUpgrade fetchmail | Dec 5, 2025 | Oct 28, 2025 |
| Ubuntu | — | Upgrade fetchmail | Oct 24, 2025 | Oct 4, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub