CVE-2008-3962

Publication date 11 September 2008

Last updated 24 July 2024


Ubuntu priority

Description

The from_format function in ssmtp.c in ssmtp 2.61 and 2.62, in certain configurations, uses uninitialized memory for the From: field of an e-mail message, which might allow remote attackers to obtain sensitive information (memory contents) in opportunistic circumstances by reading a message.

Status

Package Ubuntu Release Status
ssmtp 8.10 intrepid
Fixed 2.62-1ubuntu3
8.04 LTS hardy
Fixed 2.61-13ubuntu1.1
7.10 gutsy
Fixed 2.61-12ubuntu1.1
7.04 feisty Ignored end of life, was needed
6.06 LTS dapper
Fixed 2.61-5ubuntu0.1

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
ssmtp

Access our resources on patching vulnerabilities