On Fri, 2 May 2008, Todd N wrote:

 Double free vulnerability in Perl 5.8.8 allows context-dependent
 attackers to cause a denial of service (memory corruption and crash)
 via a crafted regular expression containing UTF8 characters.

 We are using Spamassassin 3.1.1.  It is urgent that I find out whether
 this update is relevant to our environment.  Is Spamassassin vulnerable
 to the issue that this update addresses?  Any answers would be greatly
 appreciated.

Not likely. SA doesn't interpret REs in the message, so how would an attacker submit a malicious RE?

--
 John Hardin KA7OHZ                    http://www.impsec.org/~jhardin/
 [EMAIL PROTECTED]    FALaholic #11174     pgpk -a [EMAIL PROTECTED]
 key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C  AF76 D822 E6E6 B873 2E79
-----------------------------------------------------------------------
  Usually Microsoft doesn't develop products, we buy products.
                          -- Arno Edelmann, Microsoft product manager
-----------------------------------------------------------------------
 6 days until the 63rd anniversary of VE day

Reply via email to