Lack of data validation In bogofilter
Description
The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote attackers to cause a denial of service (application crash) via mail headers that cause a line feed (LF) to be replaced by a null byte that is written to an incorrect memory address.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 0.92.8-1 | ||
debian 13 | 0.92.8-1 | ||
debian 11 | 0.92.8-1 | ||
debian 14 | 0.92.8-1 |
Aliases
1. 2. 3. 4. 5.