Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.812315
Category:Red Hat Local Security Checks
Title:RedHat Update for procmail RHSA-2017:3269-01
Summary:The remote host is missing an update for the 'procmail'; package(s) announced via the referenced advisory.
Description:Summary:
The remote host is missing an update for the 'procmail'
package(s) announced via the referenced advisory.

Vulnerability Insight:
The procmail packages contain a mail
processing tool that can be used to create mail servers, mailing lists, sort
incoming mail into separate folders or files, preprocess mail, start any program
upon mail arrival, or automatically forward selected incoming mail. Security
Fix(es): * A heap-based buffer overflow flaw was found in procmail's formail
utility. A remote attacker could send a specially crafted email that, when
processed by formail, could cause formail to crash or, possibly, execute
arbitrary code as the user running formail. (CVE-2017-16844)

Affected Software/OS:
procmail on Red Hat Enterprise Linux Server (v. 7)

Solution:
Please Install the Updated Packages.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2017-16844
Debian Security Information: DSA-4041 (Google Search)
https://www.debian.org/security/2017/dsa-4041
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=876511
https://lists.debian.org/debian-lts-announce/2017/11/msg00019.html
RedHat Security Advisories: RHSA-2017:3269
https://access.redhat.com/errata/RHSA-2017:3269
http://www.securitytracker.com/id/1039844
CopyrightCopyright (C) 2017 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.