tamirverthim / src

Public git conversion mirror of OpenBSD's official cvs src repository.
https://www.openbsd.org
0 stars 0 forks source link

CVE-2023-29323 (High) detected in src0aecda14650f9fce8577e43d2a403385b5fa5bcf #69

Open mend-for-github-com[bot] opened 1 year ago

mend-for-github-com[bot] commented 1 year ago

CVE-2023-29323 - High Severity Vulnerability

Vulnerable Library - src0aecda14650f9fce8577e43d2a403385b5fa5bcf

Public git conversion mirror of OpenBSD's official CVS src repository. Pull requests not accepted - send diffs to the tech@ mailing list.

Library home page: https://github.com/openbsd/src.git

Found in HEAD commit: 250560ac3a6cd973d828db0972dd561343848d2b

Vulnerable Source Files (2)

/usr.sbin/smtpd/envelope.c /usr.sbin/smtpd/envelope.c

Vulnerability Details

ascii_load_sockaddr in smtpd in OpenBSD before 7.1 errata 024 and 7.2 before errata 020, and OpenSMTPD Portable before 7.0.0-portable commit f748277, can abort upon a connection from a local, scoped IPv6 address.

Publish Date: 2023-04-04

URL: CVE-2023-29323

CVSS 3 Score Details (7.8)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Local - Attack Complexity: Low - Privileges Required: Low - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: High - Availability Impact: High

For more information on CVSS3 Scores, click here.