CVE-2002-1090

NameCVE-2002-1090
DescriptionBuffer overflow in read_smtp_response of protocol.c in libesmtp before 0.8.11 allows a remote SMTP server to (1) execute arbitrary code via a certain response or (2) cause a denial of service via long server responses.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libesmtp (PTS)jessie1.0.6-4fixed
stretch1.0.6-4.2fixed
buster, bullseye1.0.6-4.3fixed
bookworm1.1.0-3.1~deb12u1fixed
sid, trixie1.1.0-3.2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libesmtpsource(unstable)0.8.11-1

Search for package or bug name: Reporting problems