CVE-2017-16844Improper Restriction of Operations within the Bounds of a Memory Buffer in Procmail

Severity
9.8CRITICALNVD
OSV7.5
EPSS
22.0%
top 4.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 16
Latest updateMay 14

Description

Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted e-mail message because of a hardcoded realloc size, a different vulnerability than CVE-2014-3618.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages9 packages

🔴Vulnerability Details

2
GHSA
GHSA-4f62-c8fw-44pp: Heap-based buffer overflow in the loadbuf function in formisc2022-05-14
OSV
CVE-2017-16844: Heap-based buffer overflow in the loadbuf function in formisc2017-11-16

📋Vendor Advisories

5
Ubuntu
procmail vulnerability2017-11-21
Ubuntu
procmail vulnerability2017-11-20
Microsoft
Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code 2017-11-14
Red Hat
procmail: Heap-based buffer overflow in loadbuf function in formisc.c2017-09-22
Debian
CVE-2017-16844: procmail - Heap-based buffer overflow in the loadbuf function in formisc.c in formail in pr...2017

💬Community

2
Bugzilla
CVE-2017-16844 procmail: Heap-based buffer overflow in loadbuf function in formisc.c2017-10-09
Bugzilla
CVE-2017-16844 procmail: Heap-based buffer overflow in loadbuf function in formisc.c [fedora-all]2017-10-09