On Fri, 2 May 2008, Todd N wrote:
Double free vulnerability in Perl 5.8.8 allows context-dependent
attackers to cause a denial of service (memory corruption and crash)
via a crafted regular expression containing UTF8 characters.
We are using Spamassassin 3.1.1. It is urgent that I find out whether
this update is relevant to our environment. Is Spamassassin vulnerable
to the issue that this update addresses? Any answers would be greatly
appreciated.
Not likely. SA doesn't interpret REs in the message, so how would an
attacker submit a malicious RE?
--
John Hardin KA7OHZ http://www.impsec.org/~jhardin/
[EMAIL PROTECTED] FALaholic #11174 pgpk -a [EMAIL PROTECTED]
key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873 2E79
-----------------------------------------------------------------------
Usually Microsoft doesn't develop products, we buy products.
-- Arno Edelmann, Microsoft product manager
-----------------------------------------------------------------------
6 days until the 63rd anniversary of VE day