Out-of-bounds read in libesmtp (Debian package) - CVE-2019-19977

 

Out-of-bounds read in libesmtp (Debian package) - CVE-2019-19977

Published: August 7, 2023


Vulnerability identifier: #VU79018
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-19977
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger an out-of-bounds read error and read contents of memory on the system.


Affected software

libesmtp (Debian package)
libesmtp
libesmtp-debuginfo
libesmtp-debugsource
libesmtp-devel
libesmtp-help
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE MicroOS
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
openEuler
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)

How to mitigate CVE-2019-19977

Install updates from vendor's website.

libesmtp - addressed in versions 1.0.4-157.18.3.1, 1.0.6-17.3.1, 1.0.6-150.4.1
libesmtp-debuginfo - addressed in versions 1.0.4-157.18.3.1, 1.0.6-17.3.1, 1.0.6-150.4.1
libesmtp-debugsource - addressed in versions 1.0.4-157.18.3.1, 1.0.6-17.3.1, 1.0.6-150.4.1
libesmtp-devel - addressed in versions 1.0.6-17.3.1, 1.0.6-150.4.1
libesmtp - update to 1.0.6-19
libesmtp-help - update to 1.0.6-19
libesmtp-debuginfo - update to 1.0.6-19
libesmtp-debugsource - update to 1.0.6-19
libesmtp-devel - update to 1.0.6-19
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173

External References

Related Security Bulletins