Debian Security Advisory
DLA-46-1 procmail -- LTS security update
- Date Reported:
- 05 Sep 2014
- Affected Packages:
- Security database references:
- In the Debian bugtracking system: Bug 704675, Bug 760443.
In Mitre's CVE dictionary: CVE-2014-3618.
- More information:
piPiwinger and Tavis Ormandy reported a heap overflow vulnerability in procmail's formail utility when processing specially-crafted email headers. A remote attacker could use this flaw to cause formail to crash, resulting in a denial of service or data loss, or possibly execute arbitrary code.
For Debian 6
Squeeze, these issues have been fixed in procmail version 3.22-19+deb6u1