CVE-2014-3618

Name
CVE-2014-3618
Description
Heap-based buffer overflow in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted email header, related to "unbalanced quotes."
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit http://www.openwall.com/lists/oss-security/2014/09/03/8
DEBIAN http://www.debian.org/security/2014/dsa-3019
UBUNTU http://www.ubuntu.com/usn/USN-2340-1
BID http://www.securityfocus.com/bid/69573
SUSE http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00008.html
SUSE http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00022.html
REDHAT http://rhn.redhat.com/errata/RHSA-2014-1172.html
CONFIRM https://support.apple.com/HT205267
APPLE http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html
SECUNIA http://secunia.com/advisories/61108
SECUNIA http://secunia.com/advisories/61090
SECUNIA http://secunia.com/advisories/61076
CONFIRM http://linux.oracle.com/errata/ELSA-2014-1172.html
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/95688

Match rules

CPE URI Source package Min version Max version
cpe:2.3:o:canonical:ubuntu_linux:10.04:-:lts:*:*:*:*:* ubuntu_linux == None == 10.04
cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:* ubuntu_linux == None == 12.04
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* ubuntu_linux == None == 14.04
cpe:2.3:a:procmail:procmail:3.22:*:*:*:*:*:*:* procmail == None == 3.22

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
procmail 3.11-main 3.22-r4 Carlo Landmeter <clandmeter@gmail.com> possibly vulnerable