PT-2018-19372 · Crashmail · Crashmail
Published
2018-01-01
·
Updated
2026-03-28
·
CVE-2018-25223
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Crashmail version 1.6
Description
Crashmail 1.6 contains a stack-based buffer overflow that could allow remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can create payloads with Return-Oriented Programming (ROP) chains to achieve code execution within the application's context. Unsuccessful attempts may lead to a denial of service.
Recommendations
Update to a newer version of Crashmail that addresses this issue. As a temporary workaround, carefully validate all input received by the application to prevent excessively long strings from being processed.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Crashmail