CVE-2004-1007
published 2005-03-01CVE-2004-1007: The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote attackers to cause a denial of service (application crash) via mail headers that…
PriorityP412medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.93%
78.6th percentile
The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote attackers to cause a denial of service (application crash) via mail headers that cause a line feed (LF) to be replaced by a null byte that is written to an incorrect memory address.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bogofilter | bogofilter | >= 0 < 0.92.8-1 | 0.92.8-1 |
| bogofilter | bogofilter | >= 0 < 0.92.8-1 | 0.92.8-1 |
| bogofilter | bogofilter | >= 0 < 0.92.8-1 | 0.92.8-1 |
| bogofilter | bogofilter | >= 0 < 0.92.8-1 | 0.92.8-1 |
| bogofilter | email_filter | — | — |
| bogofilter | email_filter | — | — |
| bogofilter | email_filter | — | — |
| bogofilter | email_filter | — | — |
| bogofilter | email_filter | — | — |
| bogofilter | email_filter | — | — |
| bogofilter | email_filter | — | — |
| debian | bogofilter | < bogofilter 0.92.8-1 (bookworm) | bogofilter 0.92.8-1 (bookworm) |
| ubuntu | ubuntu_linux | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-chqq-gr5j-843v: The quoted-printable decoder in bogofilter 0
ghsa_unreviewed·2022-04-29
CVE-2004-1007 [MEDIUM] GHSA-chqq-gr5j-843v: The quoted-printable decoder in bogofilter 0
The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote attackers to cause a denial of service (application crash) via mail headers that cause a line feed (LF) to be replaced by a null byte that is written to an incorrect memory address.
OSV
CVE-2004-1007: The quoted-printable decoder in bogofilter 0
osv·2005-03-01·CVSS 5.0
CVE-2004-1007 [MEDIUM] CVE-2004-1007: The quoted-printable decoder in bogofilter 0
The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote attackers to cause a denial of service (application crash) via mail headers that cause a line feed (LF) to be replaced by a null byte that is written to an incorrect memory address.
Ubuntu
bogofilter vulnerability
vendor_ubuntu·2004-11-17
CVE-2004-1007 bogofilter vulnerability
Title: bogofilter vulnerability
Summary: bogofilter vulnerability
Antti-Juhani Kaijanaho discovered a Denial of Service vulnerability in
bogofilter. The quoted-printable decoder handled certain Base-64
encoded strings in an invalid way which caused a buffer overflow and
an immediate program abort.
The exact impact depends on the way bogofilter is integrated into the
system. In common setups, the mail that contains such malformed
headers is deferred by the mail delivery agent and remains in the
queue, where it will eventually bounce back to the sender.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2004-1007: bogofilter - The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote attack...
vendor_debian·2004·CVSS 5.0
CVE-2004-1007 [MEDIUM] CVE-2004-1007: bogofilter - The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote attack...
The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote attackers to cause a denial of service (application crash) via mail headers that cause a line feed (LF) to be replaced by a null byte that is written to an incorrect memory address.
Scope: local
bookworm: resolved (fixed in 0.92.8-1)
bullseye: resolved (fixed in 0.92.8-1)
forky: resolved (fixed in 0.92.8-1)
sid: resolved (fixed in 0.92.8-1)
trixie: resolved (fixed in 0.92.8-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2005-03-01
Published