PT-2018-19372 · Crashmail · Crashmail

Published

2018-01-01

·

Updated

2026-03-28

·

CVE-2018-25223

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Crashmail version 1.6
Description Crashmail 1.6 contains a stack-based buffer overflow that could allow remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can create payloads with Return-Oriented Programming (ROP) chains to achieve code execution within the application's context. Unsuccessful attempts may lead to a denial of service.
Recommendations Update to a newer version of Crashmail that addresses this issue. As a temporary workaround, carefully validate all input received by the application to prevent excessively long strings from being processed.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-25223

Affected Products

Crashmail