Debian Security Advisory

DLA-46-1 procmail -- LTS security update

Date Reported:
05 Sep 2014
Affected Packages:
procmail
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 704675, Bug 760443.
In Mitre's CVE dictionary: CVE-2014-3618.
More information:

Boris pi Piwinger and Tavis Ormandy reported a heap overflow vulnerability in procmail's formail utility when processing specially-crafted email headers. A remote attacker could use this flaw to cause formail to crash, resulting in a denial of service or data loss, or possibly execute arbitrary code.

For Debian 6 Squeeze, these issues have been fixed in procmail version 3.22-19+deb6u1