important · RCE — Mail
A malicious mail server can overflow an NTLM-enabled fetchmail client's stack.
Affects
fetchmail, a Unix mail-retrieval and forwarding client that may run interactively or as a system daemon.
The maintainer now says code execution may be possible on some builds, but reliable instruction-pointer control remains compiler-, ABI-, layout- and hardening-dependent.
Detail and 3 sources
Fetchmail 6.6.7 fixes the overflow and withdraws the earlier non-exploitability conclusion.
Chain to watch
Reproduce the overwrite against supported distribution packages built with NTLM enabled.→↓Measure instruction-pointer control under each package's shipped compiler and hardening configuration.→↓Whether supported concrete builds permit reliable code execution.
Unverified chainStart with NTLM-enabled distribution packages rather than a custom unhardened build.