PT-2005-1920 · Smail · Smail
Sean
·
Published
2005-03-29
·
Updated
2016-10-18
·
CVE-2005-0893
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
smail version 3.2.0.120
Description
The issue concerns a problem in the signal handlers implemented in modes.c, which uses certain unsafe library calls. This could potentially allow attackers to execute arbitrary code by exploiting signal handler race conditions, possibly leveraging xmalloc.
Recommendations
For smail version 3.2.0.120, consider applying a patch or fix that addresses the unsafe library calls in signal handlers to prevent potential code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Smail