The from_format function in ssmtp.c in ssmtp 2.61 and 2.62, in certain configurations, uses uninitialized memory for the From: field of an e-mail message, which might allow remote attackers to obtain sensitive information (memory contents) in opportunistic circumstances by reading a message.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2008-09-10 18:13
Updated : 2017-08-07 18:32
NVD link : CVE-2008-3962
Mitre link : CVE-2008-3962
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
ssmtp
- ssmtp