FW: Oxygen3 24h-365d [Buffer overflow in a spam control application - 01/29/03]

"Cagdas Funda" <[email protected]> Fri, 31 Jan 2003 10:00:57 +0200
Newsgroups gmane.mail.spam.anti-spam.turkish
Message-ID <[email protected]>

          - Buffer overflow in a spam control application -
   Oxygen3 24h-365d, by Panda Software (http://www.pandasoftware.com)

Madrid, January 30, 2003 - SecurityTracker has reported -at
http://www.securitytracker.com/alerts/2003/Jan/1005989.html - that a
vulnerability has been detected in SpamAssassin, one of the most
commonly used spam control applications.

This vulnerability is a buffer overflow that occurs when SpamAssassin
'spamc' is used in BSMTP mode (invoked with option '-B'). The buffer
overflow occurs in the escaping of '.' characters at the beginning of
SMTP lines, when the system receives a specially crafted e-mail.

An attacker could exploit this flaw to run arbitrary code or even take
control of the affected server.

NOTE: The address above may not show up on your screen as one line. This
would prevent you from using the link to access the web page. If this
happens, just use the 'cut' and 'paste' options to join the pieces of
the URL.