FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2012-5468

This CVE name corresponds to:

Entered Topic
2012-12-03 bogofilter -- heap corruption by invalid base64 input

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2012-5468
Phase Assigned(20121024)

Description

Heap-based buffer overflow in iconvert.c in the bogolexer component in Bogofilter before 1.2.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an email containing a base64 string that is decoded to incomplete multibyte characters.

References

Source Reference
MLIST [oss-security] 20121204 CVE-2012-5468: bogofilter-SA-2012-01
MISC https://bugzilla.redhat.com/show_bug.cgi?id=883358
CONFIRM http://bogofilter.sourceforge.net/security/bogofilter-SA-2012-01
CONFIRM http://bogofilter.svn.sourceforge.net/viewvc/bogofilter?view=revision&revision=6973
CONFIRM http://bogofilter.svn.sourceforge.net/viewvc/bogofilter?view=revision&revision=6975
DEBIAN DSA-2585
MANDRIVA MDVSA-2013:064
BID 56804
SECUNIA 51334
SECUNIA 51521
XF bogofilter-bogolexer-base64-dos(80524)