USN-240-1: bogofilter vulnerability

12 January 2006

bogofilter vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 5.10

Software Description

Details

A buffer overflow was found in bogofilter’s character set conversion handling. Certain invalid UTF-8 character sequences caused an invalid memory access. By sending a specially crafted email, a remote attacker could exploit this to crash bogofilter or possibly even execute arbitrary code with bogofilter’s privileges.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 5.10
bogofilter

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

References