ALT-PU-2018-1499-1
Closed vulnerabilities
Published: 2017-09-23
BDU:2017-02652
Уязвимость функции loadbuf программного средства обработки сообщений электронной почты Procmail, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Severity: CRITICAL (9.8)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
Published: 2017-11-16
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2017-16844
Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted e-mail message because of a hardcoded realloc size, a different vulnerability than CVE-2014-3618.
Severity: CRITICAL (9.8)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
- 1039844
- 1039844
- RHSA-2017:3269
- RHSA-2017:3269
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=876511
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=876511
- [debian-lts-announce] 20171118 [SECURITY] [DLA 1173-1] procmail security update
- [debian-lts-announce] 20171118 [SECURITY] [DLA 1173-1] procmail security update
- DSA-4041
- DSA-4041