Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

openSUSE 11.4: 2013:0166-1 Important: Bogofilter Heap Corruption Fix

opensuse
Calendar Grey January 23, 2013
Dist Opensuse Esm H88
The latest revision of bogofilter in openSUSE addresses critical vulnerabilities and brings various improvements, ensuring better performance and enhanced security.
An update that fixes one vulnerability is now available.

Description

- Update to version 1.2.3.

* Update configure.ac to avoid autoconf 2.68 warnings, by

(a) quoting the first AC_RUN_IFELSE argument, an

AC_LANG_PROGRAM(), with [ ], and (b) providing an

explicit "true" assumption for Berkeley DB capabilities

to avoid cross-compilation warnings.

* Security bugfix; (bnc#792939), Fix a heap corruption in

base64 decoder on invalid input.

2-01

* Added bogofilter-faq-bg.html, a Bulgarian translation

of the FAQ.

* Mark "Berkeley DB 5.1.19: (August 27, 2010)" supported.

- Update to version 1.2.2.

* Use a better PRNG for random sleeps. That is

arc4random() where available, and drand48() elsewhere.

* Assorted fixes for issues found with clang analyzer:

+ Fix a potential NULL deference

+ Fix a potential division by zero

+ Remove dead assignments and increments

* Update Doxyfile and source contrib/bogogrep.c for docs,

too.

* Security bugfix, CVE-2010-2494: Fix a heap corruption

in base64...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 11.4/standard/i586/patchinfo.28:

zypper in -t patch 2012-21

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 11.4/standard/i586/patchinfo.28 (i586 x86_64):

bogofilter-1.2.3-12.1

bogofilter-debuginfo-1.2.3-12.1

bogofilter-debugsource-1.2.3-12.1

References

https://www.suse.com/security/cve/CVE-2010-2494.html

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2013:0166-1
Rating: important
Affected Products: openSUSE 11.4/standard/i586/patchinfo.28

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here