Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in fetchmail. A stack-based buffer overflow exists in the NTLM client authentication code (ntlm_helper() / buildSmbNtlmAuthResponse() in smbutil.c) when fetchmail is built with --enable-NTLM. The AddBytes macro copies data from a server-supplied NTLM Type 2 challenge into a fixed 1024-byte stack buffer without validating remaining capacity. A malicious or compromised mail server that advertises NTLM can overwrite a few dozen bytes past the buffer. Depending on compiler stack-frame layout, this may allow remote code execution; otherwise the practical impact is authentication failure or process abort under stack hardening. Affects fetchmail 5.0.8 through 6.6.6. Fixed in 6.6.7 (commit cb5be5c38471eec19e519ace0bc569176317ea92). Red Hat Enterprise Linux builds enable NTLM and ship affected versions.