LWN.net Logo

ssmtp: memory contents disclosure

Package(s):ssmtp CVE #(s):CVE-2008-3962
Created:September 15, 2008 Updated:September 17, 2008
Description:

From the Red Hat bugzilla:

The from_format function in ssmtp.c in ssmtp 2.62, in certain configurations, uses uninitialized memory for the From: field of an e-mail message, which might allow remote attackers to obtain sensitive information (memory contents) in opportunistic circumstances by reading a message.

Alerts:
Fedora FEDORA-2008-8069 2008-09-13
Fedora FEDORA-2008-8040 2008-09-13

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds