Improper Check for Exceptional Conditions in OpenSMTPD by openSUSE
CVE-2025-62875

6.9MEDIUM

Key Information:

Vendor

Suse

Vendor
CVE Published:
20 November 2025

What is CVE-2025-62875?

A vulnerability in OpenSMTPD allows local users to exploit improper conditions, potentially leading to a denial of service (DoS). This issue can cause the email server to crash, impacting the availability of email services for users. The vulnerability affects OpenSMTPD versions on openSUSE Tumbleweed prior to 7.8.0p0-1.1. It is crucial for users and administrators to apply necessary updates to mitigate risks associated with this vulnerability.

Affected Version(s)

openSUSE Tumbleweed ? < 7.8.0p0-1.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Matthias Gerstner of SUSE
.
CVE-2025-62875 : Improper Check for Exceptional Conditions in OpenSMTPD by openSUSE