CVE-2015-7687: Use After Free
Several vulnerabilities have been fixed in OpenSMTPD 5.7.2:
- an oversight in the portable version of fgetln() that allows attackers to read and write out-of-bounds memory;
- multiple denial-of-service vulnerabilities that allow local users to kill or hang OpenSMTPD;
- a stack-based buffer overflow that allows local users to crash OpenSMTPD, or execute arbitrary code as the non-chrooted smtpd user;
- a hardlink attack (or race-conditioned symlink attack) that allows local users to unset the chflags() of arbitrary files;
- a hardlink attack that allows local users to read the first line of arbitrary files (for example, root's hash from /etc/master.passwd);
- a denial-of-service vulnerability that allows remote attackers to fill OpenSMTPD's queue or mailbox hard-disk partition;
- an out-of-bounds memory read that allows remote attackers to crash OpenSMTPD, or leak information and defeat the ASLR protection;
- a use-after-free vulnerability that allows remote attackers to crash OpenSMTPD, or execute arbitrary code as the non-chrooted smtpd user;
Further details can be found in Qualys' audit report:
http://seclists.org/oss-sec/2015/q4/17
MITRE has assigned one CVE for the use-after-free vulnerability; additional CVEs may be assigned:
http://seclists.org/oss-sec/2015/q4/23
External References:
https://www.opensmtpd.org/announces/release-5.7.2.txt http://seclists.org/oss-sec/2015/q4/17
Other sources
Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving reqcavrfysmtp and reqcavrfymta.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7687?
CVE-2015-7687 has been classified with a high severity due to its potential for causing denial-of-service and memory corruption.
How do I fix CVE-2015-7687?
To mitigate CVE-2015-7687, upgrade OpenSMTPD to version 5.7.2 or later.
What vulnerabilities are identified in CVE-2015-7687?
CVE-2015-7687 identifies multiple vulnerabilities including out-of-bounds memory access and denial-of-service conditions.
Which versions of OpenSMTPD are affected by CVE-2015-7687?
OpenSMTPD versions prior to 5.7.2 are affected by CVE-2015-7687.
Can CVE-2015-7687 lead to remote code execution?
CVE-2015-7687 does not specifically indicate the potential for remote code execution but it can lead to significant service disruption.