CVE-2023-52159

A stack-based buffer overflow vulnerability in gross 0.9.3 through 1.x before 1.0.4 allows remote attackers to trigger a denial of service (grossd daemon crash) or potentially execute arbitrary code in grossd via crafted SMTP transaction parameters that cause an incorrect strncat for a log entry.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bizdelnick:gross:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

History

20 Mar 2025, 20:15

Type Values Removed Values Added
CWE CWE-787
CPE cpe:2.3:a:bizdelnick:gross:*:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
First Time Bizdelnick gross
Debian debian Linux
Bizdelnick
Debian
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References () https://codeberg.org/bizdelnick/gross/wiki/Known-vulnerabilities#cve-2023-52159 - () https://codeberg.org/bizdelnick/gross/wiki/Known-vulnerabilities#cve-2023-52159 - Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2024/03/msg00027.html - () https://lists.debian.org/debian-lts-announce/2024/03/msg00027.html - Mailing List

21 Nov 2024, 08:39

Type Values Removed Values Added
References () https://codeberg.org/bizdelnick/gross/wiki/Known-vulnerabilities#cve-2023-52159 - () https://codeberg.org/bizdelnick/gross/wiki/Known-vulnerabilities#cve-2023-52159 -
References () https://lists.debian.org/debian-lts-announce/2024/03/msg00027.html - () https://lists.debian.org/debian-lts-announce/2024/03/msg00027.html -

25 Mar 2024, 14:15

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de desbordamiento de búfer en la región stack de la memoria en gross 0.9.3 hasta 1.x anterior a 1.0.4 permite a atacantes remotos desencadenar una denegación de servicio (caída del demonio de grossd) o potencialmente ejecutar código arbitrario en grossd a través de parámetros de transacción SMTP manipulados que causan un error strncat para una entrada de registro.
References
  • () https://lists.debian.org/debian-lts-announce/2024/03/msg00027.html -

18 Mar 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-18 02:15

Updated : 2025-03-20 20:15


NVD link : CVE-2023-52159

Mitre link : CVE-2023-52159

CVE.ORG link : CVE-2023-52159


JSON object : View

Products Affected

bizdelnick

  • gross

debian

  • debian_linux
CWE
CWE-787

Out-of-bounds Write