Description
Heap-based buffer overflow in bogofilter 0.96.2, 0.95.2, 0.94.14, 0.94.12, and other versions from 0.93.5 to 0.96.2, when using Unicode databases, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via "invalid input sequences" that lead to heap corruption when bogofilter or bogolexer converts character sets.
Affected products
- bogofilter / email_filter0.93.5 – 0.93.5
- bogofilter / email_filter0.94.12 – 0.94.12
- bogofilter / email_filter0.94.14 – 0.94.14
- bogofilter / email_filter0.95.2 – 0.95.2
- bogofilter / email_filter0.96.2 – 0.96.2
References
- VENDOR_ADVISORYhttps://usn.ubuntu.com/240-1/
- MISChttp://bogofilter.sourceforge.net/security/bogofilter-SA-2005-01
- MAILING_LISThttp://lists.suse.com/archive/suse-security-announce/2006-Feb/0001.html
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2006/0100
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/24118
- VENDOR_ADVISORYhttp://secunia.com/advisories/18717
- MISChttp://www.securityfocus.com/bid/16171
- VENDOR_ADVISORYhttp://secunia.com/advisories/18352
- VENDOR_ADVISORYhttp://secunia.com/advisories/18427
Updated 32m ago · 2 sources