PT-2015-3338 · Openbsd · Opensmtpd

Martin Prpič

·

Published

2015-10-05

·

Updated

2017-11-01

·

CVE-2015-7687

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenSMTPD versions prior to 5.7.2
Description The issue is related to a use-after-free condition that can be exploited by remote attackers to cause a denial of service or execute arbitrary code. This is achieved through vectors involving req ca vrfy smtp and req ca vrfy mta. The vulnerability allows an attacker to potentially crash the system or execute arbitrary code.
Recommendations For versions prior to 5.7.2, update to version 5.7.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the req ca vrfy smtp and req ca vrfy mta functions until a patch is available.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02492
CVE-2015-7687

Affected Products

Opensmtpd