Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-rcx8-48pc-v9q8: mail-internals use-after-free vulnerability in `vec_insert_bytes`

Incorrect reallocation logic in the function vec_insert_bytes causes a use-after-free.

This function does not have to be called directly to trigger the vulnerability because many methods on EncodingWriter call this function internally.

The mail-* suite is unmaintained and the upstream sources have been actively vandalised. A fixed mail-internals-ng (and mail-headers-ng and mail-core-ng) crate has been published which fixes this, and a dependency on another unsound crate.

ghsa
#vulnerability#git

mail-internals use-after-free vulnerability in `vec_insert_bytes`

Moderate severity GitHub Reviewed Published Aug 24, 2023 to the GitHub Advisory Database • Updated Aug 24, 2023

ghsa: Latest News

GHSA-mj5r-x73q-fjw6: SPEmailHandler-PHP has Potential Abuse for Sending Arbitrary Emails