7.8 CVE-2023-29323

Patch
 

ascii_load_sockaddr in smtpd in OpenBSD before 7.1 errata 024 and 7.2 before errata 020, and OpenSMTPD Portable before 7.0.0-portable commit f748277, can abort upon a connection from a local, scoped IPv6 address.
https://nvd.nist.gov/vuln/detail/CVE-2023-29323

Categories

CWE-NVD-noinfo

References


 

CPE

cpe start end
Configuration 1
cpe:2.3:o:openbsd:openbsd:7.2:*:*:*:*:*:*:*
cpe:2.3:a:opensmtpd:opensmtpd:*:*:*:*:*:*:*:* < 7.0.0
cpe:2.3:o:openbsd:openbsd:7.1:*:*:*:*:*:*:*


REMEDIATION


Patch

Url
https://ftp.openbsd.org/pub/OpenBSD/patches/7.2/common/020_smtpd.patch.sig
https://ftp.openbsd.org/pub/OpenBSD/patches/7.1/common/024_smtpd.patch.sig
https://github.com/OpenSMTPD/OpenSMTPD/commit/41d0eae481f538956b1f1fbadfb535043454061f
https://github.com/openbsd/src/commit/f748277ed1fc7065ae8998d61ed78b9ab1e55fae


EXPLOITS


Exploit-db.com

id description date
No known exploits

Other (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry


MITRE