Unrated severityNVD Advisory· Published Dec 31, 2005· Updated Apr 16, 2026
CVE-2005-4591
CVE-2005-4591
Description
Heap-based buffer overflow in bogofilter 0.96.2, 0.95.2, 0.94.14, 0.94.12, and other versions from 0.93.5 to 0.96.2, when using Unicode databases, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via "invalid input sequences" that lead to heap corruption when bogofilter or bogolexer converts character sets.
Affected products
5cpe:2.3:o:bogofilter:email_filter:0.93.5:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:o:bogofilter:email_filter:0.93.5:*:*:*:*:*:*:*
- cpe:2.3:o:bogofilter:email_filter:0.94.12:*:*:*:*:*:*:*
- cpe:2.3:o:bogofilter:email_filter:0.94.14:*:*:*:*:*:*:*
- cpe:2.3:o:bogofilter:email_filter:0.95.2:*:*:*:*:*:*:*
- cpe:2.3:o:bogofilter:email_filter:0.96.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- bogofilter.sourceforge.net/security/bogofilter-SA-2005-01nvdPatchVendor Advisory
- secunia.com/advisories/18352nvdPatchVendor Advisory
- www.securityfocus.com/bid/16171nvdPatch
- lists.suse.com/archive/suse-security-announce/2006-Feb/0001.htmlnvd
- secunia.com/advisories/18427nvd
- secunia.com/advisories/18717nvd
- www.vupen.com/english/advisories/2006/0100nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/24118nvd
- usn.ubuntu.com/240-1/nvd
News mentions
0No linked articles in our index yet.