Logo
vulnerabilityCVE-2014-3618
Name
CVE-2014-3618
Source
NVD ( link)Debian ( link)
Description
Heap-based buffer overflow in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted email header, related to "unbalanced quotes."
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
procmail
Patched

Vulnerability Rating#


7.5
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
3.24
Not Affected
yocto
scarthgap
3.22
Patched

Resolved with patches#


procmail (yocto:kirkstone)

#
Title
Author
Resolve
1
Patch #1
Peter Marko <peter.marko@siemens.com>
CVE-2014-3618

procmail (yocto:scarthgap)

#
Title
Author
Resolve
1
Patch #1
Peter Marko <peter.marko@siemens.com>
CVE-2014-3618