CVE-2017-16844 is a critical heap-based buffer overflow vulnerability in the loadbuf function of formail in procmail 3.22. This flaw allows remote attackers to trigger a denial of service or potentially execute arbitrary code through a specially crafted email due to a hardcoded realloc size. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk, requiring no user interaction or authentication for exploitation. While there are no known active exploits, Metasploit modules, or ExploitDB entries, the vulnerability has garnered significant community discussion, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.22CPE matchmatch criteria | cpe:2.3:a:procmail:procmail:3.22:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2017-16844
Jun 11, 2024CVE-2017-16844
Dec 14, 2021Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted e-mail message because of a hardcoded realloc size a different vulnerability than CVE-2014-3618.
Nov 14, 2017procmail: Heap-based buffer overflow in loadbuf function in formisc.c
Sep 22, 2017