5
CVSSv2

CVE-2004-1007

Published: 01/03/2005 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote malicious users to cause a denial of service (application crash) via mail headers that cause a line feed (LF) to be replaced by a null byte that is written to an incorrect memory address.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bogofilter email filter 0.92

bogofilter email filter 0.92.4

bogofilter email filter 0.9.0.3

ubuntu ubuntu linux 4.1

bogofilter email filter 0.92.6

bogofilter email filter 0.92.7

bogofilter email filter 0.9.0.4

bogofilter email filter 0.9.0.5

Vendor Advisories

Antti-Juhani Kaijanaho discovered a Denial of Service vulnerability in bogofilter The quoted-printable decoder handled certain Base-64 encoded strings in an invalid way which caused a buffer overflow and an immediate program abort ...