Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-8614

Опубликовано: 11 апр. 2016
Источник: debian
EPSS Низкий

Описание

Multiple stack-based buffer overflows in the (1) conv_jistoeuc, (2) conv_euctojis, and (3) conv_sjistoeuc functions in codeconv.c in Claws Mail before 3.13.1 allow remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
claws-mailfixed3.13.1-1package
macopixfixed1.7.4-6package
macopixno-dsajessiepackage
macopixno-dsawheezypackage

Примечания

  • http://git.claws-mail.org/?p=claws.git;a=commit;h=d390fa07f5548f3173dd9cc13b233db5ce934c82 (3.13.1)

  • http://git.claws-mail.org/?p=claws.git;a=commitdiff;h=e3ffcb455e0376053451ce968e6c71ef37708222 (not yet in tagged release)

  • Upstream patch is broken - first comparison uses wrong operator and others appear

  • to assume wrong maximum character length.

  • http://www.thewildbeast.co.uk/claws-mail/bugzilla/show_bug.cgi?id=3557

  • http://www.thewildbeast.co.uk/claws-mail/bugzilla/show_bug.cgi?id=3584

  • https://bugs.gentoo.org/show_bug.cgi?id=569010

EPSS

Процентиль: 83%
0.01873
Низкий

Связанные уязвимости

CVSS3: 7.3
ubuntu
почти 10 лет назад

Multiple stack-based buffer overflows in the (1) conv_jistoeuc, (2) conv_euctojis, and (3) conv_sjistoeuc functions in codeconv.c in Claws Mail before 3.13.1 allow remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion.

CVSS3: 7.3
nvd
почти 10 лет назад

Multiple stack-based buffer overflows in the (1) conv_jistoeuc, (2) conv_euctojis, and (3) conv_sjistoeuc functions in codeconv.c in Claws Mail before 3.13.1 allow remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion.

suse-cvrf
почти 10 лет назад

Security update for claws-mail

suse-cvrf
около 10 лет назад

Security update for claws-mail

CVSS3: 7.3
github
больше 3 лет назад

Multiple stack-based buffer overflows in the (1) conv_jistoeuc, (2) conv_euctojis, and (3) conv_sjistoeuc functions in codeconv.c in Claws Mail before 3.13.1 allow remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion.

EPSS

Процентиль: 83%
0.01873
Низкий