Описание
Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted e-mail message because of a hardcoded realloc size, a different vulnerability than CVE-2014-3618.
Релиз | Статус | Примечание |
---|---|---|
artful | released | 3.22-25ubuntu0.17.10.1 |
devel | not-affected | 3.22-26 |
esm-infra-legacy/trusty | not-affected | 3.22-21ubuntu0.2 |
esm-infra/xenial | not-affected | 3.22-25ubuntu0.16.04.1 |
precise/esm | not-affected | 3.22-19ubuntu0.2 |
trusty | released | 3.22-21ubuntu0.2 |
trusty/esm | not-affected | 3.22-21ubuntu0.2 |
upstream | released | 3.22-26 |
xenial | released | 3.22-25ubuntu0.16.04.1 |
zesty | released | 3.22-25ubuntu0.17.04.1 |
Показывать по
EPSS
10 Critical
CVSS2
9.8 Critical
CVSS3
Связанные уязвимости
Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted e-mail message because of a hardcoded realloc size, a different vulnerability than CVE-2014-3618.
Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted e-mail message because of a hardcoded realloc size, a different vulnerability than CVE-2014-3618.
Heap-based buffer overflow in the loadbuf function in formisc.c in for ...
EPSS
10 Critical
CVSS2
9.8 Critical
CVSS3