commands.c in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long SMTP command without a space character, which causes an array to be referenced with a negative index.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Qmail | Dan_bernstein | * | * |
Netqmail | Ubuntu | bionic | * |
Netqmail | Ubuntu | focal | * |
Netqmail | Ubuntu | trusty | * |
Netqmail | Ubuntu | trusty/esm | * |
Netqmail | Ubuntu | upstream | * |
Netqmail | Ubuntu | xenial | * |
Qmail | Ubuntu | trusty | * |
Qmail | Ubuntu | upstream | * |