Stack-based Buffer Overflow in Fetchmail with NTLM Support
CVE-2026-94184

8.1HIGH

What is CVE-2026-94184?

A stack-based buffer overflow vulnerability exists in Fetchmail when NTLM support is enabled. A malicious mail server can exploit this flaw by sending a specially crafted Type 2 challenge, causing Fetchmail to write beyond its allocated stack buffer. This could potentially allow for remote code execution, contingent on the specific stack frame arrangement, or might result in authentication failures or unexpected termination of the process, especially under memory hardening configurations.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Upstream acknowledges Tristan Madani as the original reporter.
.