Use-after-free in Fedora - CVE-2015-7687
Published: October 16, 2017 / Updated: August 8, 2020
Fedora
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when processing vectors involving req_ca_vrfy_smtp and req_ca_vrfy_mta. A remote attackers can cause a denial of service (crash) or execute arbitrary code.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
How to mitigate CVE-2015-7687
Sources
- http://lists.fedoraproject.org/pipermail/package-announce/2015-November/170448.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169600.html
- http://www.openwall.com/lists/oss-security/2015/10/03/1
- http://www.securityfocus.com/bid/76975
- https://bugzilla.redhat.com/show_bug.cgi?id=1268793
- https://www.opensmtpd.org/announces/release-5.7.2.txt
- https://www.qualys.com/2015/10/02/opensmtpd-audit-report.txt