CVE-2021-39272
Description
Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption when the IMAP server sends a PREAUTH response, allowing a MitM to intercept plaintext credentials.
Vulnerability
Fetchmail versions before 6.4.22 contain a vulnerability in which the client fails to enforce STARTTLS session encryption under certain circumstances [2]. Specifically, when connecting to an IMAP server that returns a PREAUTH response, fetchmail bypasses the TLS negotiation and continues communication over an unencrypted connection [1][2]. This issue was discovered as part of the "NO STARTTLS" research presented at USENIX Security 21 [1].
Exploitation
An attacker with a Meddler-in-the-Middle (MitM) position between the fetchmail client and the IMAP server can trigger the vulnerability by sending a PREAUTH response before the STARTTLS handshake completes [1]. The attacker does not need authentication or prior write access to the network segment. The expected TLS upgrade is skipped, and all subsequent commands and data (including login credentials) are transmitted in plaintext [1][2].
Impact
If exploited, fetchmail sends email retrieval commands and authentication credentials over an unencrypted connection [2]. A MitM attacker can read the plaintext traffic, potentially capturing sensitive information such as usernames and passwords for the mail server, as well as the content of fetched emails [1][2]. The compromise affects confidentiality; the attacker gains no direct code execution or privilege escalation on the fetchmail host.
Mitigation
The vulnerability is fixed in fetchmail version 6.4.22, released in August 2021 [2]. All users should upgrade to at least this version. Fetchmail 6.3.x and older are end-of-life and no longer receive security updates; users of those branches must upgrade to a supported release [3]. No workaround is available for unfixed versions. This CVE is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of this writing.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
21- Fetchmail/Fetchmaildescription
- osv-coords20 versionspkg:rpm/almalinux/fetchmailpkg:rpm/opensuse/fetchmail&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/fetchmail&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/fetchmail&distro=openSUSE%20Tumbleweedpkg:rpm/suse/fetchmail&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/fetchmail&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/fetchmail&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/fetchmail&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/fetchmail&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/fetchmail&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/fetchmail&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/fetchmail&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP2pkg:rpm/suse/fetchmail&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP3pkg:rpm/suse/fetchmail&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/fetchmail&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/fetchmail&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/fetchmail&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/fetchmail&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/fetchmail&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/fetchmail&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1
< 6.4.24-1.el8+ 19 more
- (no CPE)range: < 6.4.24-1.el8
- (no CPE)range: < 6.3.26-lp152.6.9.1
- (no CPE)range: < 6.3.26-20.17.1
- (no CPE)range: < 6.4.22-1.1
- (no CPE)range: < 6.4.22-20.20.1
- (no CPE)range: < 6.4.22-20.20.1
- (no CPE)range: < 6.4.22-20.20.1
- (no CPE)range: < 6.4.22-20.20.1
- (no CPE)range: < 6.4.22-20.20.1
- (no CPE)range: < 6.3.26-20.17.1
- (no CPE)range: < 6.3.26-20.17.1
- (no CPE)range: < 6.3.26-20.17.1
- (no CPE)range: < 6.3.26-20.17.1
- (no CPE)range: < 6.3.26-13.15.1
- (no CPE)range: < 6.4.22-20.20.1
- (no CPE)range: < 6.4.22-20.20.1
- (no CPE)range: < 6.4.22-20.20.1
- (no CPE)range: < 6.3.26-13.15.1
- (no CPE)range: < 6.4.22-20.20.1
- (no CPE)range: < 6.4.22-20.20.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L3XJ6XLEJCEZCAM5LGGD6XBCC522QLG4/mitrevendor-advisoryx_refsource_FEDORA
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VXMKSEHAQSEDCWZMAOJEGX3P3JW6QY6H/mitrevendor-advisoryx_refsource_FEDORA
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZYCYLL73NP7ALJWSDICIVSA47ZIXWSSA/mitrevendor-advisoryx_refsource_FEDORA
- security.gentoo.org/glsa/202209-14mitrevendor-advisoryx_refsource_GENTOO
- www.openwall.com/lists/oss-security/2021/08/27/3mitrex_refsource_MISC
- nostarttls.secvuln.infomitrex_refsource_MISC
- www.fetchmail.info/security.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.