4.3 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:N/I:N/A:P
6.4 Medium
AI Score
Confidence
High
0.042 Low
EPSS
Percentile
92.2%
Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers “massive memory usage.”
fedoranews.org/cms/node/2657
fedoranews.org/cms/node/2659
osvdb.org/33207
rhn.redhat.com/errata/RHSA-2007-0074.html
secunia.com/advisories/24197
secunia.com/advisories/24200
secunia.com/advisories/24250
secunia.com/advisories/24256
secunia.com/advisories/24265
secunia.com/advisories/24307
secunia.com/advisories/24889
security.gentoo.org/glsa/glsa-200703-02.xml
spamassassin.apache.org/advisories/cve-2007-0451.txt
svn.apache.org/repos/asf/spamassassin/branches/3.1/build/announcements/3.1.8.txt
www.mandriva.com/security/advisories?name=MDKSA-2007:049
www.novell.com/linux/security/advisories/2007_6_sr.html
www.redhat.com/support/errata/RHSA-2007-0075.html
www.securityfocus.com/bid/22584
www.securitytracker.com/id?1017666
www.vupen.com/english/advisories/2007/0628
exchange.xforce.ibmcloud.com/vulnerabilities/32536
issues.rpath.com/browse/RPL-1073
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10018