|
|
| |
|
| |
ssmtp: denial of service
| Package(s): | ssmtp |
CVE #(s): | |
| Created: | August 16, 2010 |
Updated: | August 18, 2010 |
| Description: |
From the Red
Hat bugzilla:
a deficiency in the way ssmtp removed trailing '\n' sequence
by processing lines beginning with a leading dot. A local user,
could send a specially-crafted e-mail message via ssmtp send-only
sendmail emulator, leading to ssmtp executable denial of service (exit with:
ssmtp: standardise() -- Buffer overflow). Different vulnerability
than CVE-2008-3962. |
| Alerts: |
|
( Log in to post comments)
|
|
|