Lucene search

K
gentooGentoo FoundationGLSA-200703-02
HistoryMar 02, 2007 - 12:00 a.m.

SpamAssassin: Long URI Denial of service

2007-03-0200:00:00
Gentoo Foundation
security.gentoo.org
12

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

0.042 Low

EPSS

Percentile

92.2%

Background

SpamAssassin is an extensible email filter used to identify junk email.

Description

SpamAssassin does not correctly handle very long URIs when scanning emails.

Impact

An attacker could cause SpamAssassin to consume large amounts of CPU and memory resources by sending one or more emails containing very long URIs.

Workaround

There is no known workaround at this time.

Resolution

All SpamAssassin users should upgrade to the latest version.

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=mail-filter/spamassassin-3.1.8"
OSVersionArchitecturePackageVersionFilename
Gentooanyallmail-filter/spamassassin< 3.1.8UNKNOWN

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

0.042 Low

EPSS

Percentile

92.2%