HIGH
smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very significant" memory leak via messages to an instance that performs many regex lookups
Published Dec 24, 2020
7.5
HIGHCVSS 3.1
EPSS 2.87%
Description
smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very significant" memory leak via messages to an instance that performs many regex lookups.
Affected products
No data.
Configuration 1
Configuration 2
OR
- 32
- 33
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://github.com/openbsd/src/commit/79a034b4aed29e965f45a13409268290c9910043 x_refsource_MISCPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5LKTFBQCHGMVPR4IZWHQIYAPM5J3LN3J/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TYAYXRV2DM5K4RU7RHCDZSA2UF6VCTRC/ vendor-advisoryx_refsource_FEDORA
- https://poolp.org/posts/2020-12-24/december-2020-opensmtpd-6.8.0p1-released-fixed-several-bugs-proposed-several-diffs-book-is-on-github/ x_refsource_MISCThird Party Advisory
- https://security.gentoo.org/glsa/202105-12 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.mail-archive.com/misc%40opensmtpd.org/msg05188.html x_refsource_MISC
| Link | Providers | Tags |
|---|---|---|
| https://github.com/openbsd/src/commit/79a034b4aed29e965f45a13409268290c9910043 | x_refsource_MISCPatchThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5LKTFBQCHGMVPR4IZWHQIYAPM5J3LN3J/ | vendor-advisoryx_refsource_FEDORA | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TYAYXRV2DM5K4RU7RHCDZSA2UF6VCTRC/ | vendor-advisoryx_refsource_FEDORA | |
| https://poolp.org/posts/2020-12-24/december-2020-opensmtpd-6.8.0p1-released-fixed-several-bugs-proposed-several-diffs-book-is-on-github/ | x_refsource_MISCThird Party Advisory | |
| https://security.gentoo.org/glsa/202105-12 | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| https://www.mail-archive.com/misc%40opensmtpd.org/msg05188.html | x_refsource_MISC |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 24, 2020
Updated Aug 4, 2024
Reserved Dec 24, 2020
Link CVE-2020-35679
CISA Vulnrichment
Updated n/a