CVE-2002-1090Improper Restriction of Operations within the Bounds of a Memory Buffer in Libesmtp

7 documents6 sources
Severity
7.5HIGHNVD
EPSS
0.9%
top 23.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 4
Latest updateApr 30

Description

Buffer overflow in read_smtp_response of protocol.c in libesmtp before 0.8.11 allows a remote SMTP server to (1) execute arbitrary code via a certain response or (2) cause a denial of service via long server responses.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

debiandebian/libesmtp< libesmtp 0.8.11-1 (bookworm)
Debianlibesmtp/libesmtp< 0.8.11-1+3
NVDlibesmtp/libesmtp0.8.11

🔴Vulnerability Details

2
GHSA
GHSA-468j-gfpv-g4hr: Buffer overflow in read_smtp_response of protocol2022-04-30
OSV
CVE-2002-1090: Buffer overflow in read_smtp_response of protocol2002-10-04

📋Vendor Advisories

2
Red Hat
security flaw2002-03-04
Debian
CVE-2002-1090: libesmtp - Buffer overflow in read_smtp_response of protocol.c in libesmtp before 0.8.11 al...2002

💬Community

2
Bugzilla
CVE-2002-1090 security flaw2018-08-16
Bugzilla
Buffer overflow in versions < 0.8.112002-06-09