USN-240-1: bogofilter vulnerability

Ubuntu Security Notice USN-240-1

11th January, 2006

bogofilter vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 5.10

Details

A buffer overflow was found in bogofilter's character set conversion
handling. Certain invalid UTF-8 character sequences caused an invalid
memory access. By sending a specially crafted email, a remote attacker
could exploit this to crash bogofilter or possibly even execute
arbitrary code with bogofilter's privileges.

Update instructions

The problem can be corrected by updating your system to the following package version:

Ubuntu 5.10:
bogofilter

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

None

References

CVE-2005-4591