GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Fri Mar 02, 2007 2:26 am Post subject: [ GLSA 200703-02 ] SpamAssassin: Long URI Denial of Service |
|
|
Gentoo Linux Security Advisory
Title: SpamAssassin: Long URI Denial of Service (GLSA 200703-02)
Severity: normal
Exploitable: remote
Date: March 02, 2007
Bug(s): #166969
ID: 200703-02
Synopsis
SpamAssassin is vulnerable to a Denial of Service attack.
Background
SpamAssassin is an extensible email filter used to identify junk email.
Affected Packages
Package: mail-filter/spamassassin
Vulnerable: < 3.1.8
Unaffected: >= 3.1.8
Architectures: All supported architectures
Description
SpamAssassin does not correctly handle very long URIs when scanning emails.
Impact
An attacker could cause SpamAssassin to consume large amounts of CPU and memory resources by sending one or more emails containing very long URIs.
Workaround
There is no known workaround at this time.
Resolution
All SpamAssassin users should upgrade to the latest version. Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=mail-filter/spamassassin-3.1.8" |
References
CVE-2007-0451 |
|