CVE-2010-2494
EPSS 3.4%
描述
Multiple buffer underflows in the base64 decoder in base64.c in (1) bogofilter and (2) bogolexer in bogofilter before 1.2.2 allow remote attackers to cause a denial of service (heap memory corruption and application crash) via an e-mail message with invalid base64 data that begins with an = (equals) character.
如何修補 CVE-2010-2494
要修補 CVE-2010-2494,請將受影響套件升級到下列已修補版本。
- Debian/bogofilter—升級至 1.2.1-3 或更新版本
CVE-2010-2494 正在被利用嗎?
低 — EPSS 為 3.4%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 1.2.1-3