The from_format function in ssmtp.c in ssmtp 2.61 and 2.62, in certain configurations, uses uninitialized memory for the From: field of an e-mail message, which might allow remote attackers to obtain sensitive information (memory contents) in opportunistic circumstances by reading a message.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2008/2597 | vdb entry vendor advisory |
https://bugs.gentoo.org/234391 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/45038 | vdb entry |
http://www.openwall.com/lists/oss-security/2008/09/11/2 | mailing list |
http://www.openwall.com/lists/oss-security/2008/09/09/6 | mailing list |
http://www.openwall.com/lists/oss-security/2008/09/09/5 | mailing list |
http://www.securityfocus.com/bid/31094 | vdb entry |