Vulnerability Bulletins

DSA-4041 procmail - security update


System information

   
Affected software Debian

Description

Jakub Wilk reported a heap-based buffer overflow vulnerability inprocmails formail utility when processing specially-crafted emailheaders. A remote attacker could use this flaw to cause formail tocrash, resulting in a denial of service or data loss.

More info:

https://www.debian.org/security/2017/dsa-4041

Standar resources

Property Value
CVE CVE-2017-1684 and DSA-4041.

Version history

Version Comments Date
1.0 Advisory issued 2017-11-20
Ministerio de Defensa
CNI
CCN
CCN-CERT