CVE-2014-3618: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 8.5% chance of exploitation in the next 30 days.

Heap-based buffer overflow in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted email header, related to "unbalanced quotes."

Affected products

  • Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 14.04 only
  • Procmail Procmail: version 3.22 only

Published 2014-09-08. Last modified 2026-06-17.