Upstream information
Description
Multiple buffer underflows in the base64 decoder in base64.c in (1) bogofilter and (2) bogolexer in bogofilter before 1.2.2 allow remote attackers to cause a denial of service (heap memory corruption and application crash) via an e-mail message with invalid base64 data that begins with an = (equals) character.NVD CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Novell/SUSE information
Novell Bugzilla entry: 619847 SUSE Security Advisories:- SUSE-SR:2010:014, published Mon, 02 Aug 2010 15:00:00 +0000
- openSUSE-SU-2010:0439-1, published Mon, 26 Jul 2010 22:08:11 +0200 (CEST)
- openSUSE-SU-2012:1648-1, published Mon, 17 Dec 2012 12:08:52 +0100 (CET)
- openSUSE-SU-2012:1650-1, published Mon, 17 Dec 2012 12:09:24 +0100 (CET)
- openSUSE-SU-2013:0166-1, published Wed, 23 Jan 2013 14:06:44 +0100 (CET)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Linux Enterprise Desktop 11 SP1 |
| sled11-sp1.x86-64 sled11-sp1.x86 SAT Patch Nr: 2666 |
| SUSE Linux Enterprise 11 GA DEBUGINFO |
| sled11.x86-64 sled11.x86 SAT Patch Nr: 2665 |
| SUSE Linux Enterprise Desktop 11 GA |
| sled11.x86-64 sled11.x86 SAT Patch Nr: 2665 |
| openSUSE 11.1 |
| |
| openSUSE 11.1 |
| |
| openSUSE 11.2 |
| |
| openSUSE 11.2 |
|
