Back
CVE-2017-16844
CRITICAL
Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted e-mail message because of a hardcoded realloc size, a different vulnerability than CVE-2014-3618.
Published: Nov 16, 2017
Modified: Jun 17, 2026
CWE-119
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| procmail | procmail | 3.22 |
GitHub Security Advisory GHSA-4f62-c8fw-44pp
Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22...
References (10)
- http://www.securitytracker.com/id/1039844 Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:3269 Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=876511 Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2017/11/msg00019.html
- https://www.debian.org/security/2017/dsa-4041 Third Party Advisory
- http://www.securitytracker.com/id/1039844 Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:3269 Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=876511 Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2017/11/msg00019.html
- https://www.debian.org/security/2017/dsa-4041 Third Party Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
12.52%
Top 4% most likely to be exploited
Threat Score
43 / 100
Data Sources
NVD
EPSS
GitHub