Off-by-one error in alterMIME 0.1.10 and 0.1.11 allows remote attackers to cause a denial of service (crash) via an x-header that causes snprintf overwrite the FFGET_FILE variable with a (null) byte.
A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Altermime | Pldaniels | 0.1.10 (including) | 0.1.10 (including) |
Altermime | Pldaniels | 0.1.11 (including) | 0.1.11 (including) |