Candidate: CVE-2017-8825 PublicDate: 2017-05-08 16:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8825 https://github.com/dinhviethoa/libetpan/releases/tag/1.8 Description: A null dereference vulnerability has been found in the MIME handling component of LibEtPan before 1.8, as used in MailCore and MailCore 2. A crash can occur in low-level/imf/mailimf.c during a failed parse of a Cc header containing multiple e-mail addresses. Ubuntu-Description: Notes: Bugs: https://github.com/dinhviethoa/libetpan/issues/274 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=862151 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_libetpan: upstream: https://github.com/dinhviethoa/libetpan/commit/1fe8fbc032ccda1db9af66d93016b49c16c1f22d upstream_libetpan: released (1.6-3) precise/esm_libetpan: DNE trusty_libetpan: ignored (reached end-of-life) trusty/esm_libetpan: DNE (trusty was needed) vivid/stable-phone-overlay_libetpan: DNE vivid/ubuntu-core_libetpan: DNE xenial_libetpan: ignored (end of standard support, was needed) yakkety_libetpan: ignored (reached end-of-life) zesty_libetpan: ignored (reached end-of-life) artful_libetpan: ignored (reached end-of-life) bionic_libetpan: not-affected (1.8.0-1) cosmic_libetpan: not-affected (1.8.0-1) disco_libetpan: not-affected (1.8.0-1) eoan_libetpan: not-affected (1.8.0-1) focal_libetpan: not-affected (1.8.0-1) groovy_libetpan: not-affected (1.8.0-1) hirsute_libetpan: not-affected (1.8.0-1) impish_libetpan: not-affected (1.8.0-1) jammy_libetpan: not-affected (1.8.0-1) devel_libetpan: not-affected (1.8.0-1)