Total vulnerabilities in the database
smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted pattern of client activity, because the filter state machine does not properly maintain the I/O channel between the SMTP engine and the filters layer.
Software | From | Fixed in |
---|---|---|
opensmtpd / opensmtpd | 6.8.0 | 6.8.0.x |
opensmtpd / opensmtpd | - | 6.8.0 |
opensmtpd / opensmtpd | 6.8.0-patch1-rc1 | 6.8.0-patch1-rc1.x |
fedoraproject / fedora | 32 | 32.x |
fedoraproject / fedora | 33 | 33.x |