CVE-2024-28054

Amavis before 2.12.3 and 2.13.x before 2.13.1, in part because of its use of MIME-tools, has an Interpretation Conflict (relative to some mail user agents) when there are multiple boundary parameters in a MIME email message. Consequently, there can be an incorrect check for banned files or malware.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.4 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
mitreCNA
---
---
CISA-ADPADP
7.4 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVEADP
---
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
Debian logo
Debian Releases
Debian Product
Codename
amavisd-new
bullseye
1:2.11.1-5+deb11u1
fixed
buster
postponed
bookworm
1:2.13.0-3+deb12u1
fixed
sid
1:2.13.0-7
fixed
trixie
1:2.13.0-7
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
amavisd-new
plucky
Fixed 1:2.13.0-6ubuntu1
released
oracular
Fixed 1:2.13.0-6ubuntu1
released
noble
Fixed 1:2.13.0-3ubuntu2
released
mantic
Fixed 1:2.13.0-3ubuntu1.1
released
jammy
Fixed 1:2.12.2-1ubuntu1.1
released
focal
Fixed 1:2.11.0-6.1ubuntu1.1
released
bionic
needs-triage
xenial
needs-triage
trusty
needs-triage