Bug#591515: ssmtp: CVE-2008-7258 buffer overflow

2010-08-22 Thread Luca Bruno
tag 591515 + unreproducible thanks Hi, Ubuntu bug-report was filed against 2.62 and contains a PoC/testcase. Current squeeze and sid contain latest 2.64, and the aforementioned testcase doesn't fail. Moreover, as it seems to be an off-by-one error, I think it was fixed in later versions, as

Bug#591515: ssmtp: CVE-2008-7258 buffer overflow

2010-08-09 Thread Michael Gilbert
On Sun, 8 Aug 2010 23:40:38 -0400, Anibal Monsalve Salazar wrote: On Tue, Aug 03, 2010 at 01:47:15PM -0400, Michael Gilbert wrote: package: ssmtp version: 2.64-4 severity: serious tags: security a buffer overflow in ssmtp: https://bugs.launchpad.net/ubuntu/+source/ssmtp/+bug/282424

Bug#591515: ssmtp: CVE-2008-7258 buffer overflow

2010-08-09 Thread Anibal Monsalve Salazar
On Mon, Aug 09, 2010 at 11:10:46AM -0400, Michael Gilbert wrote: that means that the info hasn't yet been populated in their database. it was assigned on oss-security, and sometimes it takes a many days to enter the database after that. Please don't forget we're talking about CVE-2008-7258. A CVE

Bug#591515: ssmtp: CVE-2008-7258 buffer overflow

2010-08-09 Thread Michael Gilbert
On Mon, 9 Aug 2010 21:25:37 -0400 Anibal Monsalve Salazar wrote: On Mon, Aug 09, 2010 at 11:10:46AM -0400, Michael Gilbert wrote: that means that the info hasn't yet been populated in their database. it was assigned on oss-security, and sometimes it takes a many days to enter the database

Bug#591515: ssmtp: CVE-2008-7258 buffer overflow

2010-08-08 Thread Anibal Monsalve Salazar
On Tue, Aug 03, 2010 at 01:47:15PM -0400, Michael Gilbert wrote: package: ssmtp version: 2.64-4 severity: serious tags: security a buffer overflow in ssmtp: https://bugs.launchpad.net/ubuntu/+source/ssmtp/+bug/282424 note that current code is slightly different than ubuntu, so its not entirely