SpamAssassin is vulnerable to a Denial of Service attack.
Package | mail-filter/spamassassin on all architectures |
---|---|
Affected versions | < 3.1.8 |
Unaffected versions | >= 3.1.8 |
SpamAssassin is an extensible email filter used to identify junk email.
SpamAssassin does not correctly handle very long URIs when scanning emails.
An attacker could cause SpamAssassin to consume large amounts of CPU and memory resources by sending one or more emails containing very long URIs.
There is no known workaround at this time.
All SpamAssassin users should upgrade to the latest version.
# emerge --sync # emerge --ask --oneshot --verbose ">=mail-filter/spamassassin-3.1.8"
Release date
March 02, 2007
Latest revision
March 02, 2007: 01
Severity
normal
Exploitable
remote
Bugzilla entries