Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2010-2494


Multiple buffer underflows in the base64 decoder in base64.c in (1) bogofilter and (2) bogolexer in bogofilter before 1.2.2 allow remote attackers to cause a denial of service (heap memory corruption and application crash) via an e-mail message with invalid base64 data that begins with an = (equals) character.


Published

2010-07-08T18:30:00.953

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application bogofilter bogofilter ≤ 1.2.1 Yes
Application bogofilter bogofilter 1.0.0 Yes
Application bogofilter bogofilter 1.0.1 Yes
Application bogofilter bogofilter 1.0.2 Yes
Application bogofilter bogofilter 1.0.3 Yes
Application bogofilter bogofilter 1.1.0 Yes
Application bogofilter bogofilter 1.1.1 Yes
Application bogofilter bogofilter 1.1.2 Yes
Application bogofilter bogofilter 1.1.3 Yes
Application bogofilter bogofilter 1.1.4 Yes
Application bogofilter bogofilter 1.1.5 Yes
Application bogofilter bogofilter 1.1.6 Yes
Application bogofilter bogofilter 1.1.7 Yes
Application bogofilter bogofilter 1.2.0 Yes

References