yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2025-61962
Component Overview
Vulnerability Overview
Name
CVE-2025-61962
Source
NVD (
link
)
Debian (
link
)
Description
In fetchmail before 6.5.6, the SMTP client can crash when authenticating upon receiving a 334 status code in a malformed context.
CWEs
CWE-142
Published Date
Oct 4, 2025
Updated Date
Jun 17, 2026
Workaround
-
Advisories
Analysis
#
Affected Component
Analysis
fetchmail
Patched
Vulnerability Ratings
#
5.9
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
fetchmail
buildroot
2025.02.x
6.5.6
Not Affected
fetchmail
buildroot
master
6.6.5
Not Affected
fetchmail
yocto
kirkstone
6.4.23
Not Affected
fetchmail
yocto
master
6.6.2
Not Affected
Resolved with patches
#
fetchmail (yocto:scarthgap)
#
Title
Author
Resolve
1
Security fix: avoid NULL+1 deref on invalid AUTH reply
Matthias Andree <matthias.andree@gmx.de>
CVE-2025-61962