Bug#760443: procmail: CVE-2014-3618: Heap-overflow in formail when processing specially-crafted email headers

2014-09-04 Thread Salvatore Bonaccorso
Source: procmail Version: 3.22-19 Severity: grave Tags: security patch upstream Hi, the following vulnerability was published for procmail. CVE-2014-3618[0]: Heap-overflow in procmail's formail utility when processing specially-crafted email headers If you fix the vulnerability please also

Bug#760443: procmail: CVE-2014-3618: Heap-overflow in formail when processing specially-crafted email headers

2014-09-04 Thread Santiago Vila
On Thu, Sep 04, 2014 at 08:40:23AM +0200, Salvatore Bonaccorso wrote: Source: procmail Version: 3.22-19 Severity: grave Tags: security patch upstream Hi, the following vulnerability was published for procmail. CVE-2014-3618[0]: Heap-overflow in procmail's formail utility when

Bug#760443: procmail: CVE-2014-3618: Heap-overflow in formail when processing specially-crafted email headers

2014-09-04 Thread Santiago Vila
Checked: Yes, it is the same as this bug: http://bugs.debian.org/704675 I'll fix them both in unstable with urgency=high. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#760443: procmail: CVE-2014-3618: Heap-overflow in formail when processing specially-crafted email headers

2014-09-04 Thread Santiago Vila
Hello security people. I've just fixed this in procmail 3.22-22 in unstable. The quilt patch is debian/patches/27. If there is anything else I could/should do, please say so. Thanks. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble?