Bug#557324: CVE-2009-3942

2009-11-21 Thread Emmanuel Bouthenot
Hi Giuseppe, > CVE-2009-3942[0]: > | Martin Lambers msmtp before 1.4.19, when OpenSSL is used, does not msmtp (and mpop) in Debian is not built against openssl but gnutls hence it should not be vulnerable to this exploit. Unless you disagree, i will close this bug. Regards, -- Emmanuel Bouthen

Bug#557324: CVE-2009-3942

2009-11-21 Thread Giuseppe Iuculano
Package: msmtp Version: 1.4.9-1 Severity: serious -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for msmtp. CVE-2009-3942[0]: | Martin Lambers msmtp before 1.4.19, when OpenSSL is used, does not | properly handle a '\0' c