Back
CVE-2015-7687
CRITICAL
Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving req_ca_vrfy_smtp and req_ca_vrfy_mta.
Published: Oct 16, 2017
Modified: Jun 17, 2026
CWE-416
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| openbsd | opensmtpd | * |
| fedoraproject | fedora | 22 |
| fedoraproject | fedora | 23 |
GitHub Security Advisory GHSA-hmqq-mf9r-frq9
Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial...
References (14)
- http://lists.fedoraproject.org/pipermail/package-announce/2015-November/170448.html Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169600.html Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/10/03/1 Mailing List, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/76975 Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1268793 Issue Tracking, Third Party Advisory, VDB Entry
- https://www.opensmtpd.org/announces/release-5.7.2.txt Release Notes, Vendor Advisory
- https://www.qualys.com/2015/10/02/opensmtpd-audit-report.txt Exploit, Technical Description, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-November/170448.html Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169600.html Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/10/03/1 Mailing List, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/76975 Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1268793 Issue Tracking, Third Party Advisory, VDB Entry
- https://www.opensmtpd.org/announces/release-5.7.2.txt Release Notes, Vendor Advisory
- https://www.qualys.com/2015/10/02/opensmtpd-audit-report.txt Exploit, Technical Description, Third Party Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
4.09%
Top 10% most likely to be exploited
Threat Score
40.4 / 100
Data Sources
NVD
EPSS
GitHub