Bug#591515: ssmtp: CVE-2008-7258 buffer overflow

2010-08-22 Thread Luca Bruno
tag 591515 + unreproducible thanks Hi, Ubuntu bug-report was filed against 2.62 and contains a PoC/testcase. Current squeeze and sid contain latest 2.64, and the aforementioned testcase doesn't fail. Moreover, as it seems to be an off-by-one error, I think it was fixed in later versions, as ssmtp

Bug#591515: ssmtp: CVE-2008-7258 buffer overflow

2010-08-09 Thread Michael Gilbert
On Mon, 9 Aug 2010 21:25:37 -0400 Anibal Monsalve Salazar wrote: > On Mon, Aug 09, 2010 at 11:10:46AM -0400, Michael Gilbert wrote: > >that means that the info hasn't yet been populated in their database. > >it was assigned on oss-security, and sometimes it takes a many days to > >enter the databa

Bug#591515: ssmtp: CVE-2008-7258 buffer overflow

2010-08-09 Thread Anibal Monsalve Salazar
On Mon, Aug 09, 2010 at 11:10:46AM -0400, Michael Gilbert wrote: >that means that the info hasn't yet been populated in their database. >it was assigned on oss-security, and sometimes it takes a many days to >enter the database after that. Please don't forget we're talking about CVE-2008-7258. A C

Bug#591515: ssmtp: CVE-2008-7258 buffer overflow

2010-08-09 Thread Michael Gilbert
On Sun, 8 Aug 2010 23:40:38 -0400, Anibal Monsalve Salazar wrote: > On Tue, Aug 03, 2010 at 01:47:15PM -0400, Michael Gilbert wrote: > >package: ssmtp > >version: 2.64-4 > >severity: serious > >tags: security > > > >a buffer overflow in ssmtp: > >https://bugs.launchpad.net/ubuntu/+source/ssmtp/+bug

Bug#591515: ssmtp: CVE-2008-7258 buffer overflow

2010-08-08 Thread Anibal Monsalve Salazar
On Tue, Aug 03, 2010 at 01:47:15PM -0400, Michael Gilbert wrote: >package: ssmtp >version: 2.64-4 >severity: serious >tags: security > >a buffer overflow in ssmtp: >https://bugs.launchpad.net/ubuntu/+source/ssmtp/+bug/282424 > >note that current code is slightly different than ubuntu, so its not >e