4.3 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:N/I:N/A:P
0.042 Low
EPSS
Percentile
92.2%
SpamAssassin is an extensible email filter used to identify junk email.
SpamAssassin does not correctly handle very long URIs when scanning emails.
An attacker could cause SpamAssassin to consume large amounts of CPU and memory resources by sending one or more emails containing very long URIs.
There is no known workaround at this time.
All SpamAssassin users should upgrade to the latest version.
# emerge --sync
# emerge --ask --oneshot --verbose ">=mail-filter/spamassassin-3.1.8"
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Gentoo | any | all | mail-filter/spamassassin | < 3.1.8 | UNKNOWN |