CVE Vulnerabilities

CVE-2024-28054

Interpretation Conflict

Published: Mar 18, 2024 | Modified: Nov 04, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Amavis before 2.12.3 and 2.13.x before 2.13.1, in part because of its use of MIME-tools, has an Interpretation Conflict (relative to some mail user agents) when there are multiple boundary parameters in a MIME email message. Consequently, there can be an incorrect check for banned files or malware.

Weakness

Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B’s state.

Affected Software

NameVendorStart VersionEnd Version
Amavisd-newUbuntudevel*
Amavisd-newUbuntuesm-infra/focal*
Amavisd-newUbuntufocal*
Amavisd-newUbuntujammy*
Amavisd-newUbuntumantic*
Amavisd-newUbuntunoble*
Amavisd-newUbuntuoracular*
Amavisd-newUbuntuplucky*
Amavisd-newUbuntuquesting*
Amavisd-newUbuntutrusty/esm*
Amavisd-newUbuntuupstream*

References