CVE-2017-16844
procmail: Heap-based buffer overflow in loadbuf function in formisc.c
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted e-mail message because of a hardcoded realloc size, a different vulnerability than CVE-2014-3618.
Desbordamiento de búfer basado en memoria dinámica (heap) en la función loadbuf en formisc.c en formail en la versión 3.22 de procmail permite que atacantes remotos provoquen una denegación de servicio (cierre inesperado de aplicación) o, posiblemente, ejecuten código arbitrario mediante un mensaje de email manipulado debido a un tamaño de realloc embebido. Esta es una vulnerabilidad diferente de CVE-2014-3618.
A heap-based buffer overflow flaw was found in procmail's formail utility. A remote attacker could send a specially crafted email that, when processed by formail, could cause formail to crash or, possibly, execute arbitrary code as the user running formail.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-11-16 CVE Reserved
- 2017-11-16 CVE Published
- 2023-10-27 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-122: Heap-based Buffer Overflow
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id/1039844 | Third Party Advisory | |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=876511 | Issue Tracking | |
https://lists.debian.org/debian-lts-announce/2017/11/msg00019.html | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2017:3269 | 2018-02-04 | |
https://www.debian.org/security/2017/dsa-4041 | 2018-02-04 | |
https://access.redhat.com/security/cve/CVE-2017-16844 | 2017-11-28 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1500070 | 2017-11-28 |