CVE-2023-52159: Buffer Overflow
Published Mar 18, 2024
·Updated
A stack-based buffer overflow vulnerability in gross 0.9.3 through 1.x before 1.0.4 allows remote attackers to trigger a denial of service (grossd daemon crash) or potentially execute arbitrary code in grossd via crafted SMTP transaction parameters that cause an incorrect strncat for a log entry.
Affected Software
3 affected componentsFixes available
debian/gross
1.0.2-4.1~deb11u11.0.2-4.1~deb12u11.0.2-4.1
Bizdelnick Gross>=0.9.3<1.0.4
Debian Debian Linux=10.0
Event History
Mar 18, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 AM
Description
Data Sourced
via NVD·02:15 AM
SeverityWeaknessAffected Software
Aug 1, 2024
Data Sourced
via Launchpad·04:44 PM
Description
Sep 14, 2024
Data Sourced
via Ubuntu·04:51 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-52159?
CVE-2023-52159 has a high severity rating due to the possibility of remote code execution and denial of service.
2
How do I fix CVE-2023-52159?
To fix CVE-2023-52159, update the gross package to version 1.0.4 or later.
3
What kind of vulnerability is CVE-2023-52159?
CVE-2023-52159 is a stack-based buffer overflow vulnerability.
4
What systems are affected by CVE-2023-52159?
CVE-2023-52159 affects gross versions from 0.9.3 through 1.x before 1.0.4.
5
Can CVE-2023-52159 lead to remote code execution?
Yes, CVE-2023-52159 can potentially allow remote attackers to execute arbitrary code.