FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-06-15 09:54:38 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date


These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
b495af21-9e10-11ea-9e83-0cc47ac16c9dqmail -- 64 bit integer overflows with possible remote code execution on large SMTP requests

Georgi Guninski writes:

There are several issues with qmail on 64 bit platforms - classical integer overflow, pointer with signed index and signedness problem (not counting the memory consumtion dos, which just helps).

Update: the problem with the signed index is exploitable on Freebsd 5.4 amd64 wih a lot of virtual memory.

The national vulnerability database summarizes:

Integer overflow in the stralloc_readyplus function in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large SMTP request.

Discovery 2005-05-06
Entry 2005-05-11
le 1.06.20160918_2