CVE-2012-0802
high
CVSS v3
—
CVSS v2
7.5
VIR risk
7.5
Description
Multiple buffer overflows in Spamdyke before 4.3.0 might allow remote attackers to execute arbitrary code via vectors related to "serious errors in the usage of snprintf()/vsnprintf()" in which the return values may be larger than the size of the buffer.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/48257
Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/47548
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| spamdyke | spamdyke | {"endIncluding":"4.2.1"} | |
| spamdyke | spamdyke | 3.0.0 | |
| spamdyke | spamdyke | 3.0.1 | |
| spamdyke | spamdyke | 3.1.0 | |
| spamdyke | spamdyke | 3.1.1 | |
| spamdyke | spamdyke | 3.1.2 | |
| spamdyke | spamdyke | 3.1.3 | |
| spamdyke | spamdyke | 3.1.4 | |
| spamdyke | spamdyke | 3.1.5 | |
| spamdyke | spamdyke | 3.1.6 | |
| spamdyke | spamdyke | 3.1.7 | |
| spamdyke | spamdyke | 3.1.8 | |
| spamdyke | spamdyke | 4.0.0 | |
| spamdyke | spamdyke | 4.0.1 | |
| spamdyke | spamdyke | 4.0.2 | |
| spamdyke | spamdyke | 4.0.3 | |
| spamdyke | spamdyke | 4.0.4 | |
| spamdyke | spamdyke | 4.0.5 | |
| spamdyke | spamdyke | 4.0.6 | |
| spamdyke | spamdyke | 4.0.7 | |
| spamdyke | spamdyke | 4.0.8 | |
| spamdyke | spamdyke | 4.0.9 | |
| spamdyke | spamdyke | 4.0.10 | |
| spamdyke | spamdyke | 4.1.0 | |
| spamdyke | spamdyke | 4.2.0 | |
References
- http://secunia.com/advisories/47548
- http://secunia.com/advisories/48257
- http://security.gentoo.org/glsa/glsa-201203-01.xml
- http://www.mail-archive.com/spamdyke-release%40spamdyke.org/msg00014.html
- http://www.openwall.com/lists/oss-security/2012/01/23/5
- http://www.osvdb.org/78351
- http://www.securityfocus.com/bid/51440
- http://www.spamdyke.org/documentation/Changelog.txt
- http://secunia.com/advisories/47548
- http://secunia.com/advisories/48257
- http://security.gentoo.org/glsa/glsa-201203-01.xml
- http://www.mail-archive.com/spamdyke-release%40spamdyke.org/msg00014.html
- http://www.openwall.com/lists/oss-security/2012/01/23/5
- http://www.osvdb.org/78351
- http://www.securityfocus.com/bid/51440
- http://www.spamdyke.org/documentation/Changelog.txt
CWEs
CWE-119
Verify integrity in audit chain (admin only). AS-IS.