CVE-2021-39272: Medium severity Fetchmail Fetchmail vulnerability
Published Aug 30, 2021
·Updated
Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.
Affected Software
4 affected components
Fetchmail Fetchmail<6.4.22
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Event History
Aug 30, 2021
CVE Published
via MITRE·05:05 AM
Data Sourced
via MITRE·05:05 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-39272?
CVE-2021-39272 is considered a medium severity vulnerability due to potential exposure of sensitive data through unencrypted sessions.
2
How do I fix CVE-2021-39272?
To fix CVE-2021-39272, upgrade Fetchmail to version 6.4.22 or later.
3
What versions of Fetchmail are affected by CVE-2021-39272?
Fetchmail versions prior to 6.4.22 are affected by CVE-2021-39272.
4
Does CVE-2021-39272 affect all Fedora versions?
CVE-2021-39272 specifically affects Fedora versions 33, 34, and 35 if using an affected version of Fetchmail.
5
What is the impact of CVE-2021-39272 on IMAP and PREAUTH?
CVE-2021-39272 may allow an attacker to intercept data due to a lack of mandatory STARTTLS encryption in certain IMAP PREAUTH situations.