CRITICAL
Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving req_ca_vrfy_smtp and req_ca_vrfy_mta
Published Oct 16, 2017
9.8
CRITICALCVSS 3.0
EPSS 4.04%
Description
Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving req_ca_vrfy_smtp and req_ca_vrfy_mta.
Affected products
No data.
Configuration 2
OR
- 22
- 23
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- http://lists.fedoraproject.org/pipermail/package-announce/2015-November/170448.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169600.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://www.openwall.com/lists/oss-security/2015/10/03/1 mailing-listx_refsource_MLISTMailing ListThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/76975 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1268793 x_refsource_CONFIRMIssue TrackingThird Party AdvisoryVDB Entry
- https://www.opensmtpd.org/announces/release-5.7.2.txt x_refsource_CONFIRMRelease NotesVendor Advisory
- https://www.qualys.com/2015/10/02/opensmtpd-audit-report.txt x_refsource_MISCExploitTechnical DescriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://lists.fedoraproject.org/pipermail/package-announce/2015-November/170448.html | vendor-advisoryx_refsource_FEDORAThird Party Advisory | |
| http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169600.html | vendor-advisoryx_refsource_FEDORAThird Party Advisory | |
| http://www.openwall.com/lists/oss-security/2015/10/03/1 | mailing-listx_refsource_MLISTMailing ListThird Party AdvisoryVDB Entry | |
| http://www.securityfocus.com/bid/76975 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1268793 | x_refsource_CONFIRMIssue TrackingThird Party AdvisoryVDB Entry | |
| https://www.opensmtpd.org/announces/release-5.7.2.txt | x_refsource_CONFIRMRelease NotesVendor Advisory | |
| https://www.qualys.com/2015/10/02/opensmtpd-audit-report.txt | x_refsource_MISCExploitTechnical DescriptionThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 16, 2017
Updated Aug 6, 2024
Reserved Oct 3, 2015
Link CVE-2015-7687
CISA Vulnrichment
Updated n/a