CVE-2009-3941 by Fred · 16/11/2009 Martin Lambers mpop before 1.0.19, when OpenSSL is used, does not properly handle a ‘