Debian Security Advisory
DLA-46-1 procmail -- LTS security update
- Date Reported:
- 05 Sep 2014
- Affected Packages:
- procmail
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 704675, Bug 760443.
In Mitre's CVE dictionary: CVE-2014-3618. - More information:
-
Boris
pi
Piwinger and Tavis Ormandy reported a heap overflow vulnerability in procmail's formail utility when processing specially-crafted email headers. A remote attacker could use this flaw to cause formail to crash, resulting in a denial of service or data loss, or possibly execute arbitrary code.For Debian 6
Squeeze
, these issues have been fixed in procmail version 3.22-19+deb6u1