CVE-2012-0802

high
Published 2012-06-19 · Modified 2026-04-29
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

Multiple buffer overflows in Spamdyke before 4.3.0 might allow remote attackers to execute arbitrary code via vectors related to "serious errors in the usage of snprintf()/vsnprintf()" in which the return values may be larger than the size of the buffer.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/48257

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/47548

Application impact

VendorProductVersionsFixed
spamdykespamdyke{"endIncluding":"4.2.1"}
spamdykespamdyke3.0.0
spamdykespamdyke3.0.1
spamdykespamdyke3.1.0
spamdykespamdyke3.1.1
spamdykespamdyke3.1.2
spamdykespamdyke3.1.3
spamdykespamdyke3.1.4
spamdykespamdyke3.1.5
spamdykespamdyke3.1.6
spamdykespamdyke3.1.7
spamdykespamdyke3.1.8
spamdykespamdyke4.0.0
spamdykespamdyke4.0.1
spamdykespamdyke4.0.2
spamdykespamdyke4.0.3
spamdykespamdyke4.0.4
spamdykespamdyke4.0.5
spamdykespamdyke4.0.6
spamdykespamdyke4.0.7
spamdykespamdyke4.0.8
spamdykespamdyke4.0.9
spamdykespamdyke4.0.10
spamdykespamdyke4.1.0
spamdykespamdyke4.2.0

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.