DEBIAN-CVE-2018-25223

Source
https://security-tracker.debian.org/tracker/CVE-2018-25223
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2018-25223.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2018-25223
Upstream
  • CVE-2018-25223
Published
2026-03-28T12:16:03.170Z
Modified
2026-03-29T10:00:40.588924Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code execution in the application context, with failed attempts potentially causing denial of service.

References

Affected packages

Debian:11 / crashmail

Package

Name
crashmail
Purl
pkg:deb/debian/crashmail?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.7-2
1.7-3
1.7-4
1.7-5

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2018-25223.json"

Debian:12 / crashmail

Package

Name
crashmail
Purl
pkg:deb/debian/crashmail?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.7-4
1.7-5

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2018-25223.json"

Debian:13 / crashmail

Package

Name
crashmail
Purl
pkg:deb/debian/crashmail?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.7-4
1.7-5

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2018-25223.json"

Debian:14 / crashmail

Package

Name
crashmail
Purl
pkg:deb/debian/crashmail?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.7-4
1.7-5

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2018-25223.json"