<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>69505</bug_id>
          
          <creation_ts>2004-10-30 07:14 0000</creation_ts>
          <short_desc>mail-filter/bogofilter: DOS - segmentation fault through malformed input</short_desc>
          <delta_ts>2009-07-13 22:33:25 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://bogofilter.sourceforge.net/security/bogofilter-SA-2004-01</bug_file_loc>
          <status_whiteboard>B3 [noglsa] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>tove@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>net-mail@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>tove@gentoo.org</who>
            <bug_when>2004-10-30 07:14:57 0000</bug_when>
            <thetext>All info see URL.

bogofilter-0.92.8.ebuild is not affected and in the tree.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-10-30 07:29:20 0000</bug_when>
            <thetext>Going directly to stable as we have a fixed version already.

Arches please mark bogofilter-0.92.8 stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pylon@gentoo.org</who>
            <bug_when>2004-10-30 07:44:56 0000</bug_when>
            <thetext>Works since a week on my ppc.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fmccor@gentoo.org</who>
            <bug_when>2004-10-30 08:00:02 0000</bug_when>
            <thetext>Works fine on sparc.  Done.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2004-10-30 18:37:24 0000</bug_when>
            <thetext>arm/hppa/ia64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>klieber@gentoo.org</who>
            <bug_when>2004-11-02 10:58:40 0000</bug_when>
            <thetext>marked stable on x86</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>eradicator@gentoo.org</who>
            <bug_when>2004-11-02 12:33:37 0000</bug_when>
            <thetext>stable amd64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-11-03 03:06:36 0000</bug_when>
            <thetext>Please vote on GLSA need</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-11-03 03:17:53 0000</bug_when>
            <thetext>I tend to vote for no GLSA on this one.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-11-03 04:41:18 0000</bug_when>
            <thetext>I vote no too. Attacker would send a malformed message and bogofilter, by refusing to process it, will leave it in the queue.

Closing.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>