Lucene search

K
gentooGentoo FoundationGLSA-200408-06
HistoryAug 09, 2004 - 12:00 a.m.

SpamAssassin: Denial of Service vulnerability

2004-08-0900:00:00
Gentoo Foundation
security.gentoo.org
5

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

0.035 Low

EPSS

Percentile

91.5%

Background

SpamAssassin is an extensible email filter which is used to identify spam.

Description

SpamAssassin contains an unspecified Denial of Service vulnerability.

Impact

By sending a specially crafted message an attacker could cause a Denial of Service attack against the SpamAssassin service.

Workaround

There is no known workaround at this time. All users are encouraged to upgrade to the latest available version of SpamAssassin.

Resolution

All SpamAssassin users should upgrade to the latest version:

 # emerge sync
 
 # emerge -pv ">=mail-filter/spamassassin-2.64"
 # emerge ">=mail-filter/spamassassin-2.64"
OSVersionArchitecturePackageVersionFilename
Gentooanyallmail-filter/spamassassin<= 2.63-r1UNKNOWN

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

0.035 Low

EPSS

Percentile

91.5%