Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.882806
Category:CentOS Local Security Checks
Title:CentOS Update for procmail CESA-2017:3269 centos7
Summary:Check the version of procmail
Description:Summary:
Check the version of procmail

Vulnerability Insight:
The procmail packages contain a mail
processing tool that can be used to create mail servers, mailing lists, sort
incoming mail into separate folders or files, preprocess mail, start any
program upon mail arrival, or automatically forward selected incoming mail.

Security Fix(es):

* A heap-based buffer overflow flaw was found in procmail's formail
utility. A remote attacker could send a specially crafted email that, when
processed by formail, could cause formail to crash or, possibly, execute
arbitrary code as the user running formail. (CVE-2017-16844)

Affected Software/OS:
procmail on CentOS 7

Solution:
Please Install the Updated Packages.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2017-16844
Debian Security Information: DSA-4041 (Google Search)
https://www.debian.org/security/2017/dsa-4041
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=876511
https://lists.debian.org/debian-lts-announce/2017/11/msg00019.html
RedHat Security Advisories: RHSA-2017:3269
https://access.redhat.com/errata/RHSA-2017:3269
http://www.securitytracker.com/id/1039844
CopyrightCopyright (C) 2017 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.