PT-2004-2010 · Bogofilter · Bogofilter
Published
2004-11-04
·
Updated
2017-07-11
·
CVE-2004-1007
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
bogofilter versions 0.17.4 through 0.92.7
Description:
The issue allows remote attackers to cause a denial of service, resulting in an application crash. This is achieved by exploiting the quoted-printable decoder in mail headers, which can cause a line feed to be replaced by a null byte written to an incorrect memory address.
Recommendations:
For bogofilter versions 0.17.4 through 0.92.7, update to a version that fixes the quoted-printable decoder issue to prevent remote attackers from causing a denial of service.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bogofilter