Unrated severityNVD Advisory· Published Sep 8, 2014· Updated May 6, 2026
CVE-2014-3618
CVE-2014-3618
Description
Heap-based buffer overflow in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted email header, related to "unbalanced quotes."
Affected products
4cpe:2.3:o:canonical:ubuntu_linux:10.04:-:lts:*:*:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:10.04:-:lts:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
14- www.openwall.com/lists/oss-security/2014/09/03/8nvdExploit
- linux.oracle.com/errata/ELSA-2014-1172.htmlnvd
- lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2014-09/msg00008.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2014-09/msg00022.htmlnvd
- rhn.redhat.com/errata/RHSA-2014-1172.htmlnvd
- secunia.com/advisories/61076nvd
- secunia.com/advisories/61090nvd
- secunia.com/advisories/61108nvd
- www.debian.org/security/2014/dsa-3019nvd
- www.securityfocus.com/bid/69573nvd
- www.ubuntu.com/usn/USN-2340-1nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/95688nvd
- support.apple.com/HT205267nvd
News mentions
0No linked articles in our index yet.