CVE-2023-52159Out-of-bounds Write in Gross

Severity
7.5HIGHNVD
EPSS
3.2%
top 12.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 18
Latest updateAug 1

Description

A stack-based buffer overflow vulnerability in gross 0.9.3 through 1.x before 1.0.4 allows remote attackers to trigger a denial of service (grossd daemon crash) or potentially execute arbitrary code in grossd via crafted SMTP transaction parameters that cause an incorrect strncat for a log entry.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/gross< gross 1.0.2-4.1~deb12u1 (bookworm)
NVDbizdelnick/gross0.9.31.0.4
Debianbizdelnick/gross< 1.0.2-4.1~deb11u1+3

Also affects: Debian Linux 10.0

🔴Vulnerability Details

1
OSV
CVE-2023-52159: A stack-based buffer overflow vulnerability in gross 02024-03-18

📋Vendor Advisories

2
Ubuntu
Gross vulnerability2024-08-01
Debian
CVE-2023-52159: gross - A stack-based buffer overflow vulnerability in gross 0.9.3 through 1.x before 1....2023
CVE-2023-52159 — Out-of-bounds Write in Gross | cvebase