CVE-2014-3618Improper Restriction of Operations within the Bounds of a Memory Buffer in Procmail

Severity
9.8CRITICALNVD
NVD7.5OSV7.5
EPSS
9.8%
top 7.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 8
Latest updateJun 11

Description

Heap-based buffer overflow in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted email header, related to "unbalanced quotes."

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages10 packages

Also affects: Ubuntu Linux 10.04, 12.04, 14.04

🔴Vulnerability Details

4
GHSA
GHSA-j8hf-r298-62j6: Heap-based buffer overflow in formisc2022-05-17
GHSA
GHSA-4f62-c8fw-44pp: Heap-based buffer overflow in the loadbuf function in formisc2022-05-14
OSV
CVE-2017-16844: Heap-based buffer overflow in the loadbuf function in formisc2017-11-16
OSV
CVE-2014-3618: Heap-based buffer overflow in formisc2014-09-08

📋Vendor Advisories

8
Microsoft
CVE-2014-3618: NIST NVD Details: https://nvd2024-06-11
Microsoft
Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code 2017-11-14
Red Hat
procmail: Heap-based buffer overflow in loadbuf function in formisc.c2017-09-22
Debian
CVE-2017-16844: procmail - Heap-based buffer overflow in the loadbuf function in formisc.c in formail in pr...2017
Red Hat
procmail: Heap-overflow in procmail's formail utility when processing specially-crafted email headers2014-09-04

💬Community

2
Bugzilla
procmail: memory corruption in formail2014-11-19
Bugzilla
CVE-2014-3618 procmail: Heap-overflow in procmail's formail utility when processing specially-crafted email headers2014-09-04