PT-2015-3338 · Openbsd · Opensmtpd

Martin Prpič

·

Publicado

2015-10-05

·

Atualizado

2017-11-01

·

CVE-2015-7687

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenSMTPD versions prior to 5.7.2
Description The issue is related to a use-after-free condition that can be exploited by remote attackers to cause a denial of service or execute arbitrary code. This is achieved through vectors involving req ca vrfy smtp and req ca vrfy mta. The vulnerability allows an attacker to potentially crash the system or execute arbitrary code.
Recommendations For versions prior to 5.7.2, update to version 5.7.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the req ca vrfy smtp and req ca vrfy mta functions until a patch is available.

Exploit

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02492
CVE-2015-7687

Produtos afetados

Opensmtpd