Debian Security Advisory
DSA-3019-1 procmail -- security update
- Date Reported:
- 04 Sep 2014
- Affected Packages:
- procmail
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 704675, Bug 760443.
In Mitre's CVE dictionary: CVE-2014-3618. - More information:
-
Boris
pi
Piwinger and Tavis Ormandy reported a heap overflow vulnerability in procmail's formail utility when processing specially-crafted email headers. A remote attacker could use this flaw to cause formail to crash, resulting in a denial of service or data loss, or possibly execute arbitrary code.For the stable distribution (wheezy), this problem has been fixed in version 3.22-20+deb7u1.
For the unstable distribution (sid), this problem has been fixed in version 3.22-22.
We recommend that you upgrade your procmail packages.