Bugzilla – Full Text Bug Listing |
Summary: | VUL-0: heap corruption overrun in bogofilter/bogolexer | ||
---|---|---|---|
Product: | [Novell Products] SUSE Security Incidents | Reporter: | Sebastian Krahmer <krahmer> |
Component: | General | Assignee: | Security Team bot <security-team> |
Status: | RESOLVED FIXED | QA Contact: | E-mail List <qa-bugs> |
Severity: | Normal | ||
Priority: | P5 - None | CC: | lmuelle, security-team |
Version: | unspecified | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
Whiteboard: | maint:released:11.0:34368 maint:released:11.1:34368 maint:released:11.2:34368 maint:released:sle11-sp1:34370 | ||
Found By: | --- | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Description
Sebastian Krahmer
2010-07-05 08:39:31 UTC
On Sat, Jul 03, 2010 at 10:57:20AM +0200, Matthias Andree wrote: > Affected: bogofilter <= 1.2.1 > SVN before 2010-07-03 08:40 UTC > > Not affected: bogofilter 1.2.2 (to be released) FYI, r6904 and r6906 seem to be related commits for the issue. http://bogofilter.svn.sf.net/viewvc/bogofilter/trunk/bogofilter/src/base64.c?view=log Regards, Eren CVE-2010-2494 Lars, thanks for your fast response. Please let us know when you have submitted fixed packages. I will create the patchinfos then. Requests created: 42675 42676 42677 SLE 11 and 11 SP 1 are missing. Am I correct? SLE 11 GA created request id 7043 Request 42680 is for openSUSE Factory. patchinfos submitted Update released for: bogofilter, bogofilter-debuginfo, bogofilter-debugsource Products: openSUSE 11.0 (debug, i386, ppc, x86_64) openSUSE 11.1 (debug, i586, ppc, x86_64) openSUSE 11.2 (debug, i586, x86_64) Update released for: bogofilter, bogofilter-debuginfo, bogofilter-debugsource Products: SLE-DEBUGINFO 11 (i386, x86_64) SLE-DESKTOP 11 (i386, x86_64) Update released for: bogofilter, bogofilter-debuginfo, bogofilter-debugsource Products: SLE-DESKTOP 11-SP1 (i386, x86_64) released Please make this report public readable. There is a reference from http://support.novell.com/security/cve/CVE-2010-2494.html made it public |