From d344694f96268b7cda5bcdcb927665b2e7e19af3 Mon Sep 17 00:00:00 2001 From: Matthias Andree Date: Tue, 17 Jun 2008 12:43:03 +0000 Subject: Add CVE Name CVE-2008-2711 for fetchmail-SA-2008-01. svn path=/branches/BRANCH_6-3/; revision=5196 --- NEWS | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'NEWS') diff --git a/NEWS b/NEWS index bffec103..abe43b9b 100644 --- a/NEWS +++ b/NEWS @@ -54,7 +54,7 @@ fetchmail 6.3.9 (not yet released): This bug was apparently introduced on 1998-11-27 when the bouncemail facility was modularized. The bug then made its appearance in fetchmail release 4.6.8. See also fetchmail-SA-2007-02.txt. -* CVE-2008-XXXX: Denial of service: When fetchmail logs data blobs +* CVE-2008-2711: Denial of service: When fetchmail logs data blobs (for instance, a To: header in -v -v verbose mode) in excess of 2048 bytes, it will crash, because it hands an uninitialized argument pointer (not the format string though) to vsnprintf and reads a -- cgit v1.2.3