Description
Heap-based buffer overflow in bogofilter and bogolexer 0.96.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via words that are longer than the input buffer used by flex.
Affected products
- bogofilter / email_filter0.93.5 – 0.93.5
- bogofilter / email_filter0.94.12 – 0.94.12
- bogofilter / email_filter0.94.14 – 0.94.14
- bogofilter / email_filter0.95.2 – 0.95.2
- bogofilter / email_filter0.96.2 – 0.96.2
References
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/24119
- MAILING_LISThttp://lists.suse.com/archive/suse-security-announce/2006-Feb/0001.html
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2006/0100
- VENDOR_ADVISORYhttp://secunia.com/advisories/18717
- MISChttp://www.securityfocus.com/bid/16171
- MISChttp://bogofilter.sourceforge.net/security/bogofilter-SA-2005-02
- VENDOR_ADVISORYhttp://secunia.com/advisories/18352
Updated 33m ago · 2 sources