Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Debian: DSA-2585-1 critical: bogofilter buffer overflow remote exploit

debian
Calendar Grey December 11, 2012
Debian Logo
Buffer overflow vulnerability discovered in email spam filter, posing risk for arbitrary code execution. Immediate update advised for security.
A heap-based buffer overflow was discovered in bogofilter, a software package for classifying mail messages as spam or non-spam

Summary

A heap-based buffer overflow was discovered in bogofilter, a software
package for classifying mail messages as spam or non-spam. Crafted
mail messages with invalid base64 data could lead to heap corruption
and, potentially, arbitrary code execution.

For the stable distribution (squeeze), this problem has been fixed in
version 1.2.2-2+squeeze1.

For the testing distribution (wheezy) and the unstable distribution
(sid), this problem has been fixed in version 1.2.2+dfsg1-2.

We recommend that you upgrade your bogofilter packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: bogofilter
CVE ID: CVE-2012-5468

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here