From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4j097H26ZCz36fp for ; Wed, 07 Oct 2026 10:57:15 +0000 (UTC) Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4j097972B6z34bJ for ; Wed, 07 Oct 2026 10:57:09 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mail01.ipfire.org (Postfix) with ESMTPSA id 4j09794kP3z4kK; Wed, 07 Oct 2026 10:57:09 +0000 (UTC) DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003ed25519; t=1791370629; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=33UKDKnKJ2n9+nucVXZlmYaRNQR/uuGwhbNjzh8Vsk4=; b=NsQOopNduJre0fR8w55mXt/2TWJCZHjaDjZQOjM3gQVtpReK+T6xl0kfjcByGSlDyD+azP 96j02Vrnw8hZNkCw== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003rsa; t=1791370629; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=33UKDKnKJ2n9+nucVXZlmYaRNQR/uuGwhbNjzh8Vsk4=; b=ESq4jyaZdESQsYOwI+ssBBcD2VqO7fw+98P76BSghx7U6QsQNc78xOq18QnKZdakDcFujh eNT/knk2b0LguqenHjDDdCtQxXmEf26MCBUFU1WQPrENryD0fNh98ofMeFVxz8GYy6RZPa WIGYuClfxaFlaMvXOnMqgz0hG5JieXmai2pw4bMRNVsqP+CzjA/ibLTGNTF9whPgW4iH2J fkwD0Sk3CCgtFinuWDprjnROmXPB8gOI9VfMX9RG6G3xSzJuy7oiPlalgKU+4FChpgxxsi 7zC7LcCKIc8De36nz755l6JrGfU18TXKvn3ZhBNOyc/wHWOhgdOikYz5hsNclw== From: Adolf Belka To: development@lists.ipfire.org Cc: Adolf Belka Subject: [PATCH] fetchmail: Update to version 6.6.9 Date: Wed, 7 Oct 2026 12:56:54 +0200 Message-ID: <20261007105658.104404-6-adolf.belka@ipfire.org> In-Reply-To: <20261007105658.104404-1-adolf.belka@ipfire.org> References: <20261007105658.104404-1-adolf.belka@ipfire.org> Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - Update from version 6.6.7 to 6.6.9 - No change in rootfile - Changelog 6.6.9 BUGFIXES: * When fetchmail was built with NTLM support, and a POP3 server send a malformed challenge to the authentication request, fetchmail would call strtok() on an uninitialized stack buffer and could in extreme cases read off the end of the buffer if it did not contain 0x00 or 0x20 bytes, and corrupt the first 0x20 character to 0x00. This will not allow remote code injection but can cause undefined behavior including crashes of fetchmail or corrupting one bit of memory. This is a regression introduced by commit 09f95921 that also became part of all fetchmail-6.6.7.rc1 and later release candidates and the 6.6.7 and 6.6.8 releases. It is separate from CVE-2026-94184 and just happened to be introduced anew in the same releases that fixed the mentioned CVE. Reported by Jakub Kulik, Gitlab Issue #98. * Fix missing CR when sending multi-line warning messages from daemon mode. Reported by Andrea Venturoli, Gitlab Issue #99. 6.6.8 SECURITY ADVISORY: * fetchmail 6.6.8 updates the NEWS file (which you appear to be reading) and the fetchmail-SA-2026-01 security announcement. There are no code changes since 6.6.7, but we need to prominently get the new documentation out. fetchmail-SA-2026-01 has been assigned CVE Id CVE-2026-94184. BUGFIX: * The Serbian (sr) translation was not installed due to an oversight in the po/LINGUAS file. DEVELOPER-FACING CHANGE: * The "make check-git" target in the autotools build is more verbose in case it errors out, usually due to uncommitted changes in the local checkout. TRANSLATION UPDATES were contributed by these fine people - thank you! Please welcome the new traditional Chinese translation! 非常感謝! * zh_TW: Alang Hsu [Chinese (traditional)] * sr: Мирослав Николић [Serbian] Signed-off-by: Adolf Belka --- lfs/fetchmail | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/lfs/fetchmail b/lfs/fetchmail index 6d9c4c2d5..2c1e27f3d 100644 --- a/lfs/fetchmail +++ b/lfs/fetchmail @@ -26,7 +26,7 @@ include Config SUMMARY = Full-Featured POP and IMAP Mail Retrieval Daemon -VER = 6.6.7 +VER = 6.6.9 THISAPP = fetchmail-$(VER) DL_FILE = $(THISAPP).tar.xz @@ -34,7 +34,7 @@ DL_FROM = $(URL_IPFIRE) DIR_APP = $(DIR_SRC)/$(THISAPP) TARGET = $(DIR_INFO)/$(THISAPP) PROG = fetchmail -PAK_VER = 27 +PAK_VER = 28 DEPS = @@ -48,7 +48,7 @@ objects = $(DL_FILE) $(DL_FILE) = $(DL_FROM)/$(DL_FILE) -$(DL_FILE)_BLAKE2 = 5c0a974b67e4c3392ab4de2b14eb5e34a0bff8eac48d2a5f412bfb500333df601e563d41dc26b897534a705c253222d13eb16e23dbefd0f82e945ae94cbf66ba +$(DL_FILE)_BLAKE2 = 5477413b3b90ebf90e33893e942f6c79e9995f7ed3578c05a15ed980b9aae1464b7674eebabfe63d50688e12a38a92b2a85a83a1a94b94b3b269a26945de3567 install : $(TARGET) -- 2.55.0