Ubuntu Security Notice 520-1 – Gaetan Leurent discovered a vulnerability in the APOP protocol based on MD5 collisions. As fetchmail supports the APOP protocol, this vulnerability can be used by attackers to discover a portion of the APOP user’s authentication credentials. Earl Chew discovered that fetchmail can be made to de-reference a NULL pointer when contacting SMTP servers. This vulnerability can be used by attackers who control the SMTP server to crash fetchmail and cause a denial of service.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/59614/USN-520-1.txt
Source: https://packetstormsecurity.com/files/59614/Ubuntu-Security-Notice-520-1.html