Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5hmm-p9xx-45x3

Опубликовано: 18 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

Amavis before 2.12.3 and 2.13.x before 2.13.1, in part because of its use of MIME-tools, has an Interpretation Conflict (relative to some mail user agents) when there are multiple boundary parameters in a MIME email message. Consequently, there can be an incorrect check for banned files or malware.

Amavis before 2.12.3 and 2.13.x before 2.13.1, in part because of its use of MIME-tools, has an Interpretation Conflict (relative to some mail user agents) when there are multiple boundary parameters in a MIME email message. Consequently, there can be an incorrect check for banned files or malware.

EPSS

Процентиль: 35%
0.0014
Низкий

7.4 High

CVSS3

Дефекты

CWE-436

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 1 года назад

Amavis before 2.12.3 and 2.13.x before 2.13.1, in part because of its use of MIME-tools, has an Interpretation Conflict (relative to some mail user agents) when there are multiple boundary parameters in a MIME email message. Consequently, there can be an incorrect check for banned files or malware.

CVSS3: 7.4
nvd
больше 1 года назад

Amavis before 2.12.3 and 2.13.x before 2.13.1, in part because of its use of MIME-tools, has an Interpretation Conflict (relative to some mail user agents) when there are multiple boundary parameters in a MIME email message. Consequently, there can be an incorrect check for banned files or malware.

CVSS3: 7.4
debian
больше 1 года назад

Amavis before 2.12.3 and 2.13.x before 2.13.1, in part because of its ...

CVSS3: 7.2
redos
около 1 года назад

Уязвимость amavisd-new

CVSS3: 7.2
fstec
больше 1 года назад

Уязвимость компонента MIME-tools контент-фильтра электронной почты Amavis, связанная с неправильным контролем доступа, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 35%
0.0014
Низкий

7.4 High

CVSS3

Дефекты

CWE-436