There are 2 open security issues in trixie.
2 issues left for the package maintainer to handle:
- CVE-2025-61962:
(needs triaging)
In fetchmail before 6.5.6, the SMTP client can crash when authenticating upon receiving a 334 status code in a malformed context.
- CVE-2026-94184:
(needs triaging)
A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixed stack buffer while building the NTLM authenticate response. This may lead to remote code execution depending on stack-frame layout, or to authentication failure or process termination under memory hardening.
You can find information about how to handle these issues in the security team's documentation.