7.5
CVSSv2

CVE-2015-7687

Published: 16/10/2017 Updated: 01/11/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Use-after-free vulnerability in OpenSMTPD prior to 5.7.2 allows remote malicious users to cause a denial of service (crash) or execute arbitrary code via vectors involving req_ca_vrfy_smtp and req_ca_vrfy_mta.

Vulnerable Product Search on Vulmon Subscribe to Product

openbsd opensmtpd

fedoraproject fedora 22

fedoraproject fedora 23

Vendor Advisories

Debian Bug report logs - #800787 opensmtpd: CVE-2015-7687 (and other issues without CVE yet) Package: src:opensmtpd; Maintainer for src:opensmtpd is Ryan Kavanagh <rak@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 3 Oct 2015 15:36:01 UTC Severity: grave Tags: fixed-upstream, security, ...