CVE-2008-3962
Last modified
CVE-2008-3962 is a vulnerability of currently unknown severity. The from_format function in ssmtp.c in ssmtp 2.61 and 2.62, in certain configurations, uses uninitialized memory for the From: field of an e-mail message, which might allow remote attackers to obtain sensitive information (memory contents) in opportunistic circumstances by reading a message.. EPSS estimates a 1.98% chance of exploitation in the next 30 days.
Description
The from_format function in ssmtp.c in ssmtp 2.61 and 2.62, in certain configurations, uses uninitialized memory for the From: field of an e-mail message, which might allow remote attackers to obtain sensitive information (memory contents) in opportunistic circumstances by reading a message.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ssmtp | Ssmtp | 2.61 |
| Ssmtp | Ssmtp | 2.62 |
References
- http://www.vupen.com/english/advisories/2008/2597Vendor Advisory
- http://www.vupen.com/english/advisories/2008/2597Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-3962?
How severe is CVE-2008-3962?
How do I fix CVE-2008-3962?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-3956orgchart.exe in Microsoft Organization Chart 2.00 allows use…
- CVE-2008-3957The Microsoft Windows Image Acquisition Logger ActiveX contr…
- CVE-2008-3958IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to ca…
- CVE-2008-3959IBM DB2 UDB 8.1 before FixPak 16, 8.2 before FixPak 9, and 9…
- CVE-2008-3960Unspecified vulnerability in the JDBC Applet Server Service …
- CVE-2008-3961Multiple unspecified vulnerabilities in Adobe Illustrator CS…
- CVE-2008-3963MySQL 5.0 before 5.0.66, 5.1 before 5.1.26, and 6.0 before 6…
- CVE-2008-3964Multiple off-by-one errors in libpng before 1.2.32beta01, an…
- CVE-2008-3965SQL injection vulnerability in misc.php in MyBB (aka MyBulle…
- CVE-2008-3966Multiple cross-site scripting (XSS) vulnerabilities in MyBB …
- CVE-2008-3967moderation.php in MyBB (aka MyBulletinBoard) before 1.4.1 do…
- CVE-2008-3968Cross-site scripting (XSS) vulnerability in userlist.php in …
Are you affected by CVE-2008-3962?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
