Heap-based buffer overflow in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted email header, related to "unbalanced quotes."
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade procmail. | Aug 30, 2017 | Sep 8, 2014 |
| Apple Osx Procmail | — | Upgrade macOS to the latest version | Apr 5, 2017 | Sep 8, 2014 |
| Centos_linux | — | Upgrade procmail | Dec 1, 2016 | Sep 8, 2014 |
| Debian | — | Upgrade procmail | Jul 30, 2024 | Sep 8, 2014 |
| Oracle Solaris | — | Upgrade mail/procmail to version 3.22-0.175.2.3.0.2.0 on Solaris 11.2 | May 29, 2017 | Sep 8, 2014 |
| Oracle_linux | — | Upgrade procmail | Oct 16, 2024 | Sep 8, 2014 |
| Suse | — | Upgrade procmail | Dec 18, 2015 | Sep 8, 2014 |
| Ubuntu | — | Upgrade procmail | Nov 8, 2024 | Sep 8, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub