7.5
CVSSv2

CVE-2007-3791

Published: 15/07/2007 Updated: 29/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in the w_read function in sockets.c in Cami Sardinha and Nigel Kukard policyd prior to 1.81 for Postfix allows remote malicious users to cause a denial of service and possibly execute arbitrary code via long SMTP commands. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

policyd policyd 1.71

policyd policyd 1.72

policyd policyd 1.73

policyd policyd 1.80

policyd policyd 1.74

policyd policyd 1.75

policyd policyd 1.70

policyd policyd 1.78

policyd policyd 1.79

policyd policyd 1.76

policyd policyd 1.77

Vendor Advisories

It was discovered that postfix-policyd, an anti-spam plugin for postfix, didn't correctly test lengths of incoming SMTP commands potentially allowing the remote execution of arbitrary code For the old stable distribution (sarge), this package was not present For the stable distribution (etch), this problem has been fixed in version 180-21etch1 ...