Описание
Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted e-mail message because of a hardcoded realloc size, a different vulnerability than CVE-2014-3618.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | released | 3.22-25ubuntu0.17.10.1 |
| devel | not-affected | 3.22-26 |
| esm-infra-legacy/trusty | released | 3.22-21ubuntu0.2 |
| esm-infra/xenial | released | 3.22-25ubuntu0.16.04.1 |
| precise/esm | not-affected | 3.22-19ubuntu0.2 |
| trusty | released | 3.22-21ubuntu0.2 |
| trusty/esm | released | 3.22-21ubuntu0.2 |
| upstream | released | 3.22-26 |
| xenial | released | 3.22-25ubuntu0.16.04.1 |
| zesty | released | 3.22-25ubuntu0.17.04.1 |
Показывать по
EPSS
10 Critical
CVSS2
9.8 Critical
CVSS3
Связанные уязвимости
Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted e-mail message because of a hardcoded realloc size, a different vulnerability than CVE-2014-3618.
Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted e-mail message because of a hardcoded realloc size, a different vulnerability than CVE-2014-3618.
Heap-based buffer overflow in the loadbuf function in formisc.c in for ...
EPSS
10 Critical
CVSS2
9.8 Critical
CVSS3