Secunia Security Advisory - A vulnerability has been reported in Sylpheed, which potentially can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a boundary error in the ldif_get_line() function in ldif.c when importing a LDIF file into the address book. This can be exploited to cause a stack-based buffer overflow and may allow arbitrary code execution via a specially crafted LDIF file with more than 2048 characters in a single line. Successful exploitation requires that the user is e.g. tricked into importing a malicious LDIF file.
c2fa508393b41eeeeb99dd4aad0a2c735024f7beb5bab8626d718c5dcbf141ec