{"id":"OESA-2026-4206","summary":"fetchmail security update","details":"Fetchmail is a mail retrieval daemon that can download messages from POP3, IMAP, ODMR and ETRN-based stores, with SSL/TLS security including certificate verification, and pass downloaded mail to a local SMTP or LMTP server, or a message delivery agent such as maildrop.\r\n\r\nSecurity Fix(es):\n\nA stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixed stack buffer while building the NTLM authenticate response. This may lead to remote code execution depending on stack-frame layout, or to authentication failure or process termination under memory hardening.\n\nAffects v5.0.8 through v6.6.6.(CVE-2026-94184)","modified":"2026-10-01T02:00:06.758370294Z","published":"2026-09-30T13:47:36Z","upstream":["CVE-2026-94184"],"database_specific":{"severity":"High"},"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4206"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94184"}],"affected":[{"package":{"name":"fetchmail","ecosystem":"openEuler:24.03-LTS-SP4","purl":"pkg:rpm/openEuler/fetchmail&distro=openEuler-24.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.37-3.oe2403sp4"}]}],"ecosystem_specific":{"aarch64":["fetchmail-6.4.37-3.oe2403sp4.aarch64.rpm","fetchmail-debuginfo-6.4.37-3.oe2403sp4.aarch64.rpm","fetchmail-debugsource-6.4.37-3.oe2403sp4.aarch64.rpm"],"src":["fetchmail-6.4.37-3.oe2403sp4.src.rpm"],"x86_64":["fetchmail-6.4.37-3.oe2403sp4.x86_64.rpm","fetchmail-debuginfo-6.4.37-3.oe2403sp4.x86_64.rpm","fetchmail-debugsource-6.4.37-3.oe2403sp4.x86_64.rpm"]},"database_specific":{"source":"https://repo.openeuler.org/security/data/osv/OESA-2026-4206.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}