PT-2026-96115 · Fetchmail · Fetchmail
CVE-2026-94184
·
Published
2026-09-21
·
Updated
2026-09-23
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
fetchmail versions 5.0.8 through 6.6.6
Description
A stack-based buffer overflow occurs in fetchmail when it is compiled with NTLM support. A malicious or compromised mail server that advertises NTLM authentication can send a specially crafted Type 2 challenge. This causes the application to write data beyond a fixed stack buffer during the construction of the NTLM authentication response. Depending on the stack-frame layout, this can result in remote code execution, authentication failure, or process termination due to memory hardening.
Recommendations
Update fetchmail versions 5.0.8 through 6.6.6 to a version where this issue is resolved.
As a temporary mitigation, avoid using NTLM authentication when fetching mail from untrusted servers.
Fix
RCE
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fetchmail