There are 2 open security issues in trixie.
2 issues left for the package maintainer to handle:
- CVE-2025-61962:
(needs triaging)
In fetchmail before 6.5.6, the SMTP client can crash when authenticating upon receiving a 334 status code in a malformed context.
- CVE-2026-94184:
(needs triaging)
A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixed stack buffer while building the NTLM authenticate response. This may lead to remote code execution depending on stack-frame layout, or to authentication failure or process termination under memory hardening. Affects v5.0.8 through v6.6.6.
You can find information about how to handle these issues in the security team's documentation.