FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2012-0802

This CVE name corresponds to:

Entered Topic
2012-01-23 spamdyke -- Buffer Overflow Vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2012-0802
Phase Assigned(20120119)

Description

Multiple buffer overflows in Spamdyke before 4.3.0 might allow remote attackers to execute arbitrary code via vectors related to "serious errors in the usage of snprintf()/vsnprintf()" in which the return values may be larger than the size of the buffer.

References

Source Reference
MLIST [oss-security] 20120123 Re: CVE request: spamdyke buffer overflow vulnerability
MLIST [spamdyke-release] 20120115 New version: spamdyke 4.3.0
CONFIRM http://www.spamdyke.org/documentation/Changelog.txt
GENTOO GLSA-201203-01
BID 51440
OSVDB 78351
SECUNIA 47548
SECUNIA 48257