title 1148731 fetchmail: CVE-2026-94184 fixes NTLM authentication
found 1148731 6.6.6
fixed 1148731 6.6.8
thanks
I had already released fetchmail 6.6.7 to fix this bug but its shipping
text files "NEWS" and "fetchmail-SA-2026-01.txt" are misleading in that
version.
* Please skip 6.6.7
* upgrade to 6.6.8, which also adds the sr translation to the install
and adds a new zh_TW translation, too.
* to assist sizeof(long)==4 aka 32-bit platforms, you may also want to
cherry-pick
https://gitlab.com/fetchmail/fetchmail/-/commit/d2480f3d5698c2fc891070554650514097194b4d
to fix two minor glitches, one of them can however crash a self-test.
Am 22.09.26 um 20:42 schrieb Salvatore Bonaccorso:
Source: fetchmail
Version: 6.6.6-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for fetchmail.
CVE-2026-94184[0]:
| A stack-based buffer overflow flaw was found in fetchmail when built
| with NTLM support. A malicious or compromised mail server
| advertising NTLM authentication can send a crafted Type 2 challenge
| that causes fetchmail to write past a fixed stack buffer while
| building the NTLM authenticate response. This may lead to remote
| code execution depending on stack-frame layout, or to authentication
| failure or process termination under memory hardening. Affects
| v5.0.8 through v6.6.6.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-94184
https://www.cve.org/CVERecord?id=CVE-2026-94184
[1] https://www.fetchmail.info/fetchmail-SA-2026-01.txt
[2]
https://gitlab.com/fetchmail/fetchmail/-/commit/cb5be5c38471eec19e519ace0bc569176317ea92
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore