Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2012:1652-1 Important: Bogofilter Heap Corruption, DoS Threat

suse
Calendar Grey December 17, 2012
Dist Suse Esm H88
This critical SUSE Security Update resolves a memory corruption vulnerability in bogofilter, potentially enabling DoS attacks.
An update that fixes one vulnerability is now available

Summary

A heap corruption in bogofilter's base64 decoding function, caused by incomplete multibyte characters, could have resulted in a Denial of Service (App. crash) or potentially allowed the execution of arbitrary code. This has been fixed. Security Issue reference: * CVE-2012-5468 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Desktop 11 SP2: zypper in -t patch sledsp2-bogofilter-7135 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Desktop 11 SP2 (i586 x86_64): bogofilter-1.1.1-174.27.1

References

#792939

Cross- CVE-2012-5468

Affected Products:

SUSE Linux Enterprise Desktop 11 SP2

https://www.suse.com/security/cve/CVE-2012-5468.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2012:1652-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here