Procmail Formail Utility 'formisc.c' Heap Overflow Vulnerability
BID:69573
CVE-2014-3618 |Info
Procmail Formail Utility 'formisc.c' Heap Overflow Vulnerability
| Bugtraq ID: | 69573 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2014-3618 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 03 2014 12:00AM |
| Updated: | Nov 03 2015 07:53PM |
| Credit: | Tavis Ormandy |
| Vulnerable: |
Ubuntu Ubuntu Linux 14.04 LTS Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise Server 11 SP3 for VMware SuSE SUSE Linux Enterprise Server 11 SP3 SuSE Suse Linux Enterprise Desktop 11 SP3 S.u.S.E. openSUSE 13.1 S.u.S.E. openSUSE 12.3 Procmail Procmail 3.22 Oracle Solaris 11.2 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 IBM TSSC 7.3.16 IBM TSSC 7.3.15 IBM TSSC 7.3 IBM TSSC 7.0 IBM SmartCloud Provisioning 2.1 3 IBM SmartCloud Provisioning 2.1 2 IBM SmartCloud Provisioning 2.1.0.1 IBM SmartCloud Provisioning 2.1 IBM Security Network Intrusion Prevention System GX7800 4.6.2 IBM Security Network Intrusion Prevention System GX7800 4.6.1 IBM Security Network Intrusion Prevention System GX7800 4.6 IBM Security Network Intrusion Prevention System GX7800 4.5 IBM Security Network Intrusion Prevention System GX7800 4.4 IBM Security Network Intrusion Prevention System GX7800 4.3 IBM Security Network Intrusion Prevention System GX7412-10 4.6.2 IBM Security Network Intrusion Prevention System GX7412-10 4.6.1 IBM Security Network Intrusion Prevention System GX7412-10 4.6 IBM Security Network Intrusion Prevention System GX7412-10 4.5 IBM Security Network Intrusion Prevention System GX7412-10 4.4 IBM Security Network Intrusion Prevention System GX7412-10 4.3 IBM Security Network Intrusion Prevention System GX7412-05 4.6.2 IBM Security Network Intrusion Prevention System GX7412-05 4.6.1 IBM Security Network Intrusion Prevention System GX7412-05 4.6 IBM Security Network Intrusion Prevention System GX7412-05 4.5 IBM Security Network Intrusion Prevention System GX7412-05 4.4 IBM Security Network Intrusion Prevention System GX7412-05 4.3 IBM Security Network Intrusion Prevention System GX7412 4.6.2 IBM Security Network Intrusion Prevention System GX7412 4.6.1 IBM Security Network Intrusion Prevention System GX7412 4.6 IBM Security Network Intrusion Prevention System GX7412 4.5 IBM Security Network Intrusion Prevention System GX7412 4.4 IBM Security Network Intrusion Prevention System GX7412 4.3 IBM Security Network Intrusion Prevention System GX6116 4.6.2 IBM Security Network Intrusion Prevention System GX6116 4.6.1 IBM Security Network Intrusion Prevention System GX6116 4.6 IBM Security Network Intrusion Prevention System GX6116 4.5 IBM Security Network Intrusion Prevention System GX6116 4.4 IBM Security Network Intrusion Prevention System GX6116 4.3 IBM Security Network Intrusion Prevention System GX5208-v2 4.6.2 IBM Security Network Intrusion Prevention System GX5208-v2 4.6.1 IBM Security Network Intrusion Prevention System GX5208-v2 4.6 IBM Security Network Intrusion Prevention System GX5208-v2 4.5 IBM Security Network Intrusion Prevention System GX5208-v2 4.4 IBM Security Network Intrusion Prevention System GX5208-v2 4.3 IBM Security Network Intrusion Prevention System GX5208 4.6.2 IBM Security Network Intrusion Prevention System GX5208 4.6.1 IBM Security Network Intrusion Prevention System GX5208 4.6 IBM Security Network Intrusion Prevention System GX5208 4.5 IBM Security Network Intrusion Prevention System GX5208 4.4 IBM Security Network Intrusion Prevention System GX5208 4.3 IBM Security Network Intrusion Prevention System GX5108-v2 4.6.2 IBM Security Network Intrusion Prevention System GX5108-v2 4.6.1 IBM Security Network Intrusion Prevention System GX5108-v2 4.6 IBM Security Network Intrusion Prevention System GX5108-v2 4.5 IBM Security Network Intrusion Prevention System GX5108-v2 4.4 IBM Security Network Intrusion Prevention System GX5108-v2 4.3 IBM Security Network Intrusion Prevention System GX5108 4.6.2 IBM Security Network Intrusion Prevention System GX5108 4.6.1 IBM Security Network Intrusion Prevention System GX5108 4.6 IBM Security Network Intrusion Prevention System GX5108 4.5 IBM Security Network Intrusion Prevention System GX5108 4.4 IBM Security Network Intrusion Prevention System GX5108 4.3 IBM Security Network Intrusion Prevention System GX5008-v2 4.6.2 IBM Security Network Intrusion Prevention System GX5008-v2 4.6.1 IBM Security Network Intrusion Prevention System GX5008-v2 4.6 IBM Security Network Intrusion Prevention System GX5008-v2 4.5 IBM Security Network Intrusion Prevention System GX5008-v2 4.4 IBM Security Network Intrusion Prevention System GX5008-v2 4.3 IBM Security Network Intrusion Prevention System GX5008 4.6.2 IBM Security Network Intrusion Prevention System GX5008 4.6.1 IBM Security Network Intrusion Prevention System GX5008 4.6 IBM Security Network Intrusion Prevention System GX5008 4.5 IBM Security Network Intrusion Prevention System GX5008 4.4 IBM Security Network Intrusion Prevention System GX5008 4.3 IBM Security Network Intrusion Prevention System GX4004-v2 4.6.2 IBM Security Network Intrusion Prevention System GX4004-v2 4.6.1 IBM Security Network Intrusion Prevention System GX4004-v2 4.6 IBM Security Network Intrusion Prevention System GX4004-v2 4.5 IBM Security Network Intrusion Prevention System GX4004-v2 4.4 IBM Security Network Intrusion Prevention System GX4004-v2 4.3 IBM Security Network Intrusion Prevention System GX4004 4.6.2 IBM Security Network Intrusion Prevention System GX4004 4.6.1 IBM Security Network Intrusion Prevention System GX4004 4.6 IBM Security Network Intrusion Prevention System GX4004 4.5 IBM Security Network Intrusion Prevention System GX4004 4.4 IBM Security Network Intrusion Prevention System GX4004 4.3 IBM Security Network Intrusion Prevention System GX4002 4.6.2 IBM Security Network Intrusion Prevention System GX4002 4.6.1 IBM Security Network Intrusion Prevention System GX4002 4.6 IBM Security Network Intrusion Prevention System GX4002 4.5 IBM Security Network Intrusion Prevention System GX4002 4.4 IBM Security Network Intrusion Prevention System GX4002 4.3 IBM Security Network Intrusion Prevention System GX3002 4.6.2 IBM Security Network Intrusion Prevention System GX3002 4.6.1 IBM Security Network Intrusion Prevention System GX3002 4.6 IBM Security Network Intrusion Prevention System GX3002 4.5 IBM Security Network Intrusion Prevention System GX3002 4.4 IBM Security Network Intrusion Prevention System GX3002 4.3 IBM Security Network Intrusion Prevention System GV200 4.6.2 IBM Security Network Intrusion Prevention System GV200 4.6.1 IBM Security Network Intrusion Prevention System GV200 4.6 IBM Security Network Intrusion Prevention System GV200 4.5 IBM Security Network Intrusion Prevention System GV200 4.4 IBM Security Network Intrusion Prevention System GV200 4.3 IBM Security Network Intrusion Prevention System GV1000 4.6.2 IBM Security Network Intrusion Prevention System GV1000 4.6.1 IBM Security Network Intrusion Prevention System GV1000 4.6 IBM Security Network Intrusion Prevention System GV1000 4.5 IBM Security Network Intrusion Prevention System GV1000 4.4 IBM Security Network Intrusion Prevention System GV1000 4.3 EMC ViPR SRM 3.6.0 EMC M&R 6.5 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 6 Avaya Proactive Contact 5.1 Avaya Proactive Contact 5.0 Avaya one-X Client Enablement Services 6.2 Avaya one-X Client Enablement Services 6.1.2 Avaya one-X Client Enablement Services 6.1.1 Avaya one-X Client Enablement Services 6.1 SP3 Avaya one-X Client Enablement Services 6.1 SP2 Avaya one-X Client Enablement Services 6.1 SP1 Avaya one-X Client Enablement Services 6.1 Avaya one-X Client Enablement Services 6.0 Avaya Message Networking 6.2.0 Avaya IQ 5.2 Avaya IQ 5.1.1 Avaya IQ 5.1 Avaya IQ 5 Avaya IP Office Server Edition 9.0 Avaya IP Office Server Edition 8.1 Avaya IP Office Application Server 9.0 SP 2 Avaya IP Office Application Server 9.0 SP 1 Avaya IP Office Application Server 9.0 Avaya IP Office Application Server 8.1 Avaya IP Office Application Server 8.0 Avaya Communication Server 1000M Signaling Server 7.6 Avaya Communication Server 1000M Signaling Server 7.5 Avaya Communication Server 1000M Signaling Server 7.0 Avaya Communication Server 1000M Signaling Server 6.0 Avaya Communication Server 1000M Signaling Server 5.5 Avaya Communication Server 1000M 7.6 Avaya Communication Server 1000M 7.5 Avaya Communication Server 1000M 7.0 Avaya Communication Server 1000M 6.0 Avaya Communication Server 1000M 5.5 Avaya Communication Server 1000E Signaling Server 7.6 Avaya Communication Server 1000E Signaling Server 7.5 Avaya Communication Server 1000E Signaling Server 7.0 Avaya Communication Server 1000E Signaling Server 6.0 Avaya Communication Server 1000E Signaling Server 5.5 Avaya Communication Server 1000E 7.6 Avaya Communication Server 1000E 7.5 Avaya Communication Server 1000E 7.0 Avaya Communication Server 1000E 6.0 Avaya CMS R17ac.h Avaya CMS R17ac.g Avaya CMS r17 Avaya Aura System Manager 6.2.3 Avaya Aura System Manager 6.2 SP3 Avaya Aura System Manager 6.2 Avaya Aura System Manager 6.1.7 Avaya Aura System Manager 6.1.5 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 Avaya Aura Experience Portal 6.0.2 Avaya Aura Experience Portal 6.0.1 Avaya Aura Experience Portal 7.0 Avaya Aura Experience Portal 6.0 SP2 Avaya Aura Experience Portal 6.0 SP1 Avaya Aura Experience Portal 6.0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 7.2 Avaya Aura Conferencing 7.0 Standard Avaya Aura Conferencing 7.0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 SP1 Standard Avaya Aura Conferencing 6.0 Avaya Aura Communication Manager Utility Services 6.3 Avaya Aura Communication Manager Utility Services 6.2.5.0.15 Avaya Aura Communication Manager Utility Services 6.2.4.0.15 Avaya Aura Communication Manager Utility Services 6.2 Avaya Aura Communication Manager Utility Services 6.1.0.9.8 Avaya Aura Communication Manager Utility Services 6.1 SP 6.1.0.9.8 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Application Server 5300 SIP Core 3.0 PB5 Avaya Aura Application Server 5300 SIP Core 3.0 PB3 Avaya Aura Application Server 5300 SIP Core 3.0 Avaya Aura Application Server 5300 SIP Core 2.1 Avaya Aura Application Server 5300 SIP Core 2.0 PB28 Avaya Aura Application Server 5300 SIP Core 2.0 PB26 Avaya Aura Application Server 5300 SIP Core 2.0 PB25 Avaya Aura Application Server 5300 SIP Core 2.0 PB23 Avaya Aura Application Server 5300 SIP Core 2.0 PB19 Avaya Aura Application Server 5300 SIP Core 2.0 PB16 Avaya Aura Application Server 5300 SIP Core 2.0 Apple Mac Os X 10.10.5 Apple Mac OS X 10.10 Apple Mac OS X 10.9.5 Apple Mac OS X 10.9.1 Apple Mac OS X 10.8.5 Apple Mac OS X 10.8.4 Apple Mac OS X 10.8.2 Apple Mac OS X 10.8.1 Apple Mac OS X 10.8 Apple Mac OS X 10.7 Apple Mac OS X 10.9.4 Apple Mac OS X 10.9.3 Apple Mac OS X 10.9.2 Apple Mac OS X 10.9 Apple Mac OS X 10.8.3 Apple Mac OS X 10.7.5 Apple Mac OS X 10.7.4 Apple Mac OS X 10.7.3 Apple Mac OS X 10.7.1 Apple Mac OS X 10.6.8 Apple Mac Os X 10.10.4 Apple Mac Os X 10.10.3 Apple Mac OS X 10.10.2 Apple Mac OS X 10.10.1 |
| Not Vulnerable: |
IBM TSSC 7.3.17 EMC ViPR SRM 3.6.1 EMC M&R 6.5u1 Apple Mac Os X 10.11 |
Discussion
Procmail Formail Utility 'formisc.c' Heap Overflow Vulnerability
The Formail utility of Procmail is prone to a heap-based buffer-overflow vulnerability.
An attacker may leverage this issue to crash the affected application, denying services to legitimate users. Other attacks may also be possible.
Procmail 3.22 is vulnerable; other versions may also be affected.
The Formail utility of Procmail is prone to a heap-based buffer-overflow vulnerability.
An attacker may leverage this issue to crash the affected application, denying services to legitimate users. Other attacks may also be possible.
Procmail 3.22 is vulnerable; other versions may also be affected.
Exploit / POC
Procmail Formail Utility 'formisc.c' Heap Overflow Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
Procmail Formail Utility 'formisc.c' Heap Overflow Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Procmail Formail Utility 'formisc.c' Heap Overflow Vulnerability
References:
References: