procmail 3.22

CPE Details

procmail 3.22
3.22
2014-09-08
20h02 +00:00
2014-09-08
20h03 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:procmail:procmail:3.22:*:*:*:*:*:*:*

Informations

Vendor

procmail

Product

procmail

Version

3.22

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2017-16844 2017-11-16 14h00 +00:00 Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted e-mail message because of a hardcoded realloc size, a different vulnerability than CVE-2014-3618.
9.8
Critical
CVE-2014-3618 2014-09-08 12h00 +00:00 Heap-based buffer overflow in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted email header, related to "unbalanced quotes."
7.5
CVE-1999-0475 1999-09-29 02h00 +00:00 A race condition in how procmail handles .procmailrc files allows a local user to read arbitrary files available to the user who is running procmail.
1.2