Oval Definition:oval:com.redhat.rhsa:def:20173269
Revision Date:2017-11-28Version:635
Title:RHSA-2017:3269: procmail security update (Important)
Description:The procmail packages contain a mail processing tool that can be used to create mail servers, mailing lists, sort incoming mail into separate folders or files, preprocess mail, start any program upon mail arrival, or automatically forward selected incoming mail.

Security Fix(es):

  • A heap-based buffer overflow flaw was found in procmail's formail utility. A remote attacker could send a specially crafted email that, when processed by formail, could cause formail to crash or, possibly, execute arbitrary code as the user running formail. (CVE-2017-16844)
  • Family:unixClass:patch
    Status:Reference(s):CVE-2017-16844
    RHSA-2017:3269
    RHSA-2017:3269-00
    RHSA-2017:3269-01
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND procmail is earlier than 0:3.22-36.el7_4.1
  • AND procmail is signed with Red Hat redhatrelease2 key
  • BACK