PT-2026-105023 · Azure Linux · Fetchmail

Published

2026-09-21

·

Updated

2026-09-21

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixed stack buffer while building the NTLM authenticate response. This may lead to remote code execution depending on stack-frame layout, or to authentication failure or process termination under memory hardening.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-105066

Affected Products

Fetchmail