LWN.net Logo

bogofilter: denial of service

Package(s):bogofilter CVE #(s):CVE-2010-2494
Created:July 27, 2010 Updated:January 23, 2013
Description: From the CVE entry:

Multiple buffer underflows in the base64 decoder in base64.c in (1) bogofilter and (2) bogolexer in bogofilter before 1.2.2 allow remote attackers to cause a denial of service (heap memory corruption and application crash) via an e-mail message with invalid base64 data that begins with an = (equals) character.

Alerts:
Ubuntu USN-980-1 2010-08-31
Fedora FEDORA-2010-13154 2010-08-20
Fedora FEDORA-2010-13139 2010-08-20
SUSE SUSE-SR:2010:014 2010-08-02
Pardus 2010-99 2010-08-02
openSUSE openSUSE-SU-2010:0439-1 2010-07-27
openSUSE openSUSE-SU-2012:1648-1 2012-12-17
openSUSE openSUSE-SU-2012:1650-1 2012-12-17
openSUSE openSUSE-SU-2013:0166-1 2013-01-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds