CVE-2012-3482: Fetchmail

Medium severity, CVSS 5.8. EPSS: 1.9% chance of exploitation in the next 30 days.

Fetchmail 5.0.8 through 6.3.21, when using NTLM authentication in debug mode, allows remote NTLM servers to (1) cause a denial of service (crash and delayed delivery of inbound mail) via a crafted NTLM response that triggers an out-of-bounds read in the base64 decoder, or (2) obtain sensitive information from memory via an NTLM Type 2 message with a crafted Target Name structure, which triggers an out-of-bounds read.

Affected products

  • Fetchmail Fetchmail: version 5.0.8 only; version 5.1.0 only; version 5.1.4 only; version 5.2.0 only; version 5.2.1 only; version 5.2.3 only; …

Published 2012-12-21. Last modified 2026-06-16.