procmail vulnerability

Related Vulnerabilities: CVE-2014-3618  

formail could be made to crash or run programs if it processed specially crafted mail.

Tavis Ormandy discovered that the formail tool incorrectly handled certain malformed mail headers. An attacker could use this flaw to cause formail to crash, resulting in a denial of service, or possibly execute arbitrary code.

4 September 2014

procmail vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 14.04 LTS
  • Ubuntu 12.04 LTS
  • Ubuntu 10.04 LTS

Summary

formail could be made to crash or run programs if it processed specially crafted mail.

Software Description

  • procmail - Versatile e-mail processor

Details

Tavis Ormandy discovered that the formail tool incorrectly handled certain malformed mail headers. An attacker could use this flaw to cause formail to crash, resulting in a denial of service, or possibly execute arbitrary code.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 14.04 LTS
procmail - 3.22-21ubuntu0.1
Ubuntu 12.04 LTS
procmail - 3.22-19ubuntu0.1
Ubuntu 10.04 LTS
procmail - 3.22-18ubuntu1.1

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

References