{ "id": "CVE-2023-52159", "sourceIdentifier": "cve@mitre.org", "published": "2024-03-18T02:15:06.053", "lastModified": "2024-03-25T14:15:09.267", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "A stack-based buffer overflow vulnerability in gross 0.9.3 through 1.x before 1.0.4 allows remote attackers to trigger a denial of service (grossd daemon crash) or potentially execute arbitrary code in grossd via crafted SMTP transaction parameters that cause an incorrect strncat for a log entry." }, { "lang": "es", "value": "Una vulnerabilidad de desbordamiento de b\u00fafer en la regi\u00f3n stack de la memoria en gross 0.9.3 hasta 1.x anterior a 1.0.4 permite a atacantes remotos desencadenar una denegaci\u00f3n de servicio (ca\u00edda del demonio de grossd) o potencialmente ejecutar c\u00f3digo arbitrario en grossd a trav\u00e9s de par\u00e1metros de transacci\u00f3n SMTP manipulados que causan un error strncat para una entrada de registro." } ], "metrics": {}, "references": [ { "url": "https://codeberg.org/bizdelnick/gross/wiki/Known-vulnerabilities#cve-2023-52159", "source": "cve@mitre.org" }, { "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00027.html", "source": "cve@mitre.org" } ] }