CVE-2021-36386

report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 49%
Affected Products (NVD)
VendorProductVersion
fetchmailfetchmail
𝑥
< 6.4.20
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
fetchmail
bookworm
6.4.37-1
fixed
bullseye
6.4.16-4+deb11u1
fixed
sid
6.4.39-1
fixed
trixie
6.4.39-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
fetchmail
bionic
needs-triage
focal
needs-triage
hirsute
ignored
impish
not-affected
jammy
not-affected
kinetic
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
dne
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
fetchmail
suse enterprise sap 12 SP3
6.3.26-13.12.1
fixed
suse enterprise sap 12 SP4
6.3.26-13.12.1
fixed
suse enterprise sap 12 SP5
6.3.26-13.18.1
fixed
suse enterprise sap 15
6.4.22-20.20.1
fixed
suse enterprise sap 15 SP1
6.4.22-20.20.1
fixed
suse enterprise server 12 SP2
6.3.26-13.12.1
fixed
suse enterprise server 12 SP3
6.3.26-13.18.1
fixed
suse enterprise server 12 SP4
6.3.26-13.12.1
fixed
suse enterprise server 12 SP5
6.3.26-13.18.1
fixed
suse enterprise server 15
6.4.22-20.20.1
fixed
suse enterprise server 15 SP1
6.4.22-20.20.1
fixed
fetchmailconf
suse enterprise sap 12 SP3
6.3.26-13.12.1
fixed
suse enterprise sap 12 SP4
6.3.26-13.12.1
fixed
suse enterprise sap 12 SP5
6.3.26-13.18.1
fixed
suse enterprise sap 15
6.4.22-20.20.1
fixed
suse enterprise sap 15 SP1
6.4.22-20.20.1
fixed
suse enterprise server 12 SP2
6.3.26-13.12.1
fixed
suse enterprise server 12 SP3
6.3.26-13.18.1
fixed
suse enterprise server 12 SP4
6.3.26-13.12.1
fixed
suse enterprise server 12 SP5
6.3.26-13.18.1
fixed
suse enterprise server 15
6.4.22-20.20.1
fixed
suse enterprise server 15 SP1
6.4.22-20.20.1
fixed