CVE-2023-52159: Bizdelnick Gross

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

A stack-based buffer overflow vulnerability in gross 0.9.3 through 1.x before 1.0.4 allows remote attackers to trigger a denial of service (grossd daemon crash) or potentially execute arbitrary code in grossd via crafted SMTP transaction parameters that cause an incorrect strncat for a log entry.

Affected products

  • Bizdelnick Gross: from 0.9.3, before 1.0.4 (fixed in 1.0.4)
  • Debian Debian Linux: version 10.0 only

Published 2024-03-18. Last modified 2026-06-17.