CVE-2014-3618
procmail - security update
EPSS 8.5%
Description
Heap-based buffer overflow in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted email header, related to "unbalanced quotes."
How to fix CVE-2014-3618
To remediate CVE-2014-3618, upgrade the affected package to a fixed version below.
- Debian/procmail—upgrade to 3.22-22 or later
- Debian/procmail—upgrade to 3.22-19+deb6u1 or later
- Debian/procmail—upgrade to 3.22-20+deb7u1 or later
Is CVE-2014-3618 being exploited?
Moderate — EPSS is 8.5%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (3)
- from 0, < 3.22-22
- from 0, < 3.22-19+deb6u1
- from 0, < 3.22-20+deb7u1