[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247974

 
 

909

 
 

194654

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2969-1 libemail-address-perl -- libemail-address-perl

ID: oval:org.secpod.oval:def:601699Date: (C)2014-07-11   (M)2022-10-10
Class: PATCHFamily: unix




Bastian Blank reported a denial of service vulnerability in Email::Address, a Perl module for RFC 2822 address parsing and creation. Email::Address::parse used significant time on parsing empty quoted strings. A remote attacker able to supply specifically crafted input to an application using Email::Address for parsing, could use this flaw to mount a denial of service attack against the application.

Platform:
Debian 7.0
Product:
libemail-address-perl
Reference:
DSA-2969-1
CVE-2014-0477
CVE    1
CVE-2014-0477
CPE    2
cpe:/a:email::address_module_project:libemail-address-perl
cpe:/o:debian:debian_linux:7.x

© SecPod Technologies