Bugzilla – Bug 1190069
VUL-0: CVE-2021-39272: fetchmail: STARTTLS session encryption bypassing
Last modified: 2022-09-30 13:43:48 UTC
Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH. References: https://www.fetchmail.info/fetchmail-SA-2021-02.txt http://www.openwall.com/lists/oss-security/2021/08/27/3 https://www.fetchmail.info/security.html References: https://bugzilla.redhat.com/show_bug.cgi?id=1999190 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-39272 http://www.openwall.com/lists/oss-security/2021/08/27/3 http://seclists.org/oss-sec/2021/q3/137 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39272 http://www.cvedetails.com/cve/CVE-2021-39272/ https://www.fetchmail.info/security.html https://nostarttls.secvuln.info/
Affected products: - SUSE:SLE-11:Update/fetchmail 6.3.8.90 - SUSE:SLE-12:Update/fetchmail 6.3.26 - SUSE:SLE-15:Update/fetchmail 6.3.26 - openSUSE:Factory/fetchmail 6.4.21 Upstream released a new version (6.4.22rc3) that fixes the problem. I extracted a list of related commit but probably is not enough to backport the fixes to older versions. Please analyze the new version in order to create the patches. - https://gitlab.com/fetchmail/fetchmail/-/commit/3837f0e2e42b43c69b46d240adcbbe3a2c68ce95 - https://gitlab.com/fetchmail/fetchmail/-/commit/8517491d8558e202a33294ac61f2268ef802f03f - https://gitlab.com/fetchmail/fetchmail/-/commit/c78cc2fc202f6bb6b44412f9c35bf176261c25f1 - https://gitlab.com/fetchmail/fetchmail/-/commit/e7199006808bb19f58d232da02172ee820d2d83e - https://gitlab.com/fetchmail/fetchmail/-/commit/b82c3ccb65e3279996a690ebf577263d7730e0b3
I can see dozens of related commits since version 6.4.21 and the documentation should also be updated accordingly. I think we can update to version 6.4.22 once released, but if it takes too long we can use the RC3. The back-port might take some time and effort.
i think we can also wait for the next release if its coming soon, in light together with the ECO update.
I'll update Factory and SLE-15-SP4 to version 6.4.22 which has just been released: * https://sourceforge.net/projects/fetchmail/files/branch_6.4/
Factory submission: https://build.opensuse.org/request/show/923570
Created attachment 853020 [details] Proposed patch for SLE-15 and SLE-12 For SLE-15 and SLE-12 this patch contains all the required changes.
openSUSE-SU-2021:3493-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1190069 CVE References: CVE-2021-39272 JIRA References: Sources used: openSUSE Leap 15.3 (src): fetchmail-6.3.26-20.17.1
SUSE-SU-2021:3493-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1190069 CVE References: CVE-2021-39272 JIRA References: Sources used: SUSE Linux Enterprise Module for Desktop Applications 15-SP3 (src): fetchmail-6.3.26-20.17.1 SUSE Linux Enterprise Module for Desktop Applications 15-SP2 (src): fetchmail-6.3.26-20.17.1 SUSE Linux Enterprise Module for Basesystem 15-SP3 (src): fetchmail-6.3.26-20.17.1 SUSE Linux Enterprise Module for Basesystem 15-SP2 (src): fetchmail-6.3.26-20.17.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2021:3492-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1190069 CVE References: CVE-2021-39272 JIRA References: Sources used: SUSE Linux Enterprise Server 12-SP5 (src): fetchmail-6.3.26-13.15.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2021:1416-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1190069 CVE References: CVE-2021-39272 JIRA References: Sources used: openSUSE Leap 15.2 (src): fetchmail-6.3.26-lp152.6.9.1
openSUSE-SU-2021:4018-1: An update that solves two vulnerabilities, contains three features and has four fixes is now available. Category: security (moderate) Bug References: 1152964,1174075,1181400,1188875,1190069,1190896 CVE References: CVE-2021-36386,CVE-2021-39272 JIRA References: SLE-17903,SLE-18059,SLE-18159 Sources used: openSUSE Leap 15.3 (src): fetchmail-6.4.22-20.20.1
SUSE-SU-2021:4018-1: An update that solves two vulnerabilities, contains three features and has four fixes is now available. Category: security (moderate) Bug References: 1152964,1174075,1181400,1188875,1190069,1190896 CVE References: CVE-2021-36386,CVE-2021-39272 JIRA References: SLE-17903,SLE-18059,SLE-18159 Sources used: SUSE Linux Enterprise Server for SAP 15-SP1 (src): fetchmail-6.4.22-20.20.1 SUSE Linux Enterprise Server for SAP 15 (src): fetchmail-6.4.22-20.20.1 SUSE Linux Enterprise Server 15-SP1-LTSS (src): fetchmail-6.4.22-20.20.1 SUSE Linux Enterprise Server 15-SP1-BCL (src): fetchmail-6.4.22-20.20.1 SUSE Linux Enterprise Server 15-LTSS (src): fetchmail-6.4.22-20.20.1 SUSE Linux Enterprise Module for Desktop Applications 15-SP3 (src): fetchmail-6.4.22-20.20.1 SUSE Linux Enterprise Module for Desktop Applications 15-SP2 (src): fetchmail-6.4.22-20.20.1 SUSE Linux Enterprise Module for Basesystem 15-SP3 (src): fetchmail-6.4.22-20.20.1 SUSE Linux Enterprise Module for Basesystem 15-SP2 (src): fetchmail-6.4.22-20.20.1 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src): fetchmail-6.4.22-20.20.1 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src): fetchmail-6.4.22-20.20.1 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): fetchmail-6.4.22-20.20.1 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): fetchmail-6.4.22-20.20.1 SUSE Enterprise Storage 6 (src): fetchmail-6.4.22-20.20.1 SUSE CaaS Platform 4.0 (src): fetchmail-6.4.22-20.20.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2021:1591-1: An update that solves two vulnerabilities, contains three features and has four fixes is now available. Category: security (moderate) Bug References: 1152964,1174075,1181400,1188875,1190069,1190896 CVE References: CVE-2021-36386,CVE-2021-39272 JIRA References: SLE-17903,SLE-18059,SLE-18159 Sources used: openSUSE Leap 15.2 (src): fetchmail-6.4.22-lp152.6.12.1
done, closing