Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Rainer Gerhards, the rsyslog project leader, reported a vulnerability in Rsyslog, a system for log processing. As a consequence of this vulnerability an attacker can send malformed messages to a server, if this one accepts data from untrusted sources, and trigger a denial of . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3040-1
SpamAssassin and Vipul's Razor are vulnerable to a Denial of Service attack when handling certain malformed messages.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200506-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: SpamAssassin 3, Vipul's Razor: Denial of Service vulnerability Date: June 21, 2005 Bugs: #94722, #95492 ID: 200506-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= SpamAssassin and Vipul's Razor are vulnerable to a Denial of Service attack when handling certain malformed messages. Background ========= SpamAssassin is an extensible email filter which is used to identify junk email. Vipul's Razor is a client for a distributed, collaborative spam detection and filtering network. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 mail-filter/spamassassin < 3.0.4 > = 3.0.4 < 3.0.1 2 mail-filter/razor < 2.71 > = 2.71 ------------------------------------------------------------------- 2 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== SpamAssassin and Vipul's Razor contain a Denial of Service vulnerability when handling special misformatted long message headers. Impact ===== By sending a specially crafted message an attacker could cause a Denial of Service attack against the SpamAssassin/Vipul's Razorserver. Workaround ========= There is no known workaround at this time. Resolution ========= All SpamAssassin users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =mail-filter/spamassassin-3.0.4" All Vipul's Razor users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =mail-filter/razor-2.71" References ========= [ 1 ] CAN-2005-1266 https://www.cve.org/CVERecord?id=CVE-CAN-2005-1266 [ 2 ] SpamAssassin Announcement https://lists.apache.org/thread/%
SpamAssassin is vulnerable to a Denial of Service attack when handling certain malformed messages.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200408-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: SpamAssassin: Denial of Service vulnerability Date: August 09, 2004 Bugs: #59483 ID: 200408-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= SpamAssassin is vulnerable to a Denial of Service attack when handling certain malformed messages. Background ========= SpamAssassin is an extensible email filter which is used to identify spam. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 mail-filter/spamassassin = 2.64 Description ========== SpamAssassin contains an unspecified Denial of Service vulnerability. Impact ===== By sending a specially crafted message an attacker could cause a Denial of Service attack against the SpamAssassin service. Workaround ========= There is no known workaround at this time. All users are encouraged to upgrade to the latest available version of SpamAssassin. Resolution ========= All SpamAssassin users should upgrade to the latest version: # emerge sync # emerge -pv "> =mail-filter/spamassassin-2.64" # emerge "> =mail-filter/spamassassin-2.64" References ========= [ 1 ] SpamAssassin Release Announcement http://marc.theaimsgroup.com/?l=spamassassin-announce&m=109168121628767&w=2 Availability =========== This GLSA and any updates to it areavailable for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200408-06 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.