REDHAT-BUG-2537395: Buffer Overflow

Published Sep 21, 2026
·
Updated

A flaw was found in fetchmail. A stack-based buffer overflow exists in the NTLM client authentication code (ntlmhelper() / buildSmbNtlmAuthResponse() in smbutil.c) when fetchmail is built with --enable-NTLM. The AddBytes macro copies data from a server-supplied NTLM Type 2 challenge into a fixed 1024-byte stack buffer without validating remaining capacity. A malicious or compromised mail server that advertises NTLM can overwrite a few dozen bytes past the buffer. Depending on compiler stack-frame layout, this may allow remote code execution; otherwise the practical impact is authentication failure or process abort under stack hardening. Affects fetchmail 5.0.8 through 6.6.6. Fixed in 6.6.7 (commit cb5be5c38471eec19e519ace0bc569176317ea92). Red Hat Enterprise Linux builds enable NTLM and ship affected versions.

Affected Software

1 affected component
Fetchmail Fetchmail>=5.0.8<=6.6.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade fetchmail to a version that resolves this vulnerability.

    Fixed in 6.6.7

Event History

Sep 21, 2026
Data Sourced
via Red Hat·01:46 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Which deployments are exposed to this flaw?

Fetchmail versions 5.0.8 through 6.6.6 are affected when built with NTLM support enabled. Red Hat Enterprise Linux builds enable NTLM and ship affected versions.

2

What must an attacker control to trigger the overflow?

An attacker needs to operate or compromise a mail server that advertises NTLM authentication and sends a crafted NTLM Type 2 challenge to the fetchmail client. The vulnerable data is copied from that server-supplied challenge into a fixed stack buffer.

3

What is the likely impact of exploitation?

Depending on compiler stack-frame layout, the overflow may permit remote code execution. On systems with stack hardening, the more likely result may be fetchmail authentication failure or a process abort.

4

What version contains the fix?

The issue is fixed in fetchmail 6.6.7.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203