SpamAssassin and Vipul's Razor are vulnerable to a Denial of Service attack when handling certain malformed messages.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200506-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: SpamAssassin 3, Vipul's Razor: Denial of Service vulnerability Date: June 21, 2005 Bugs: #94722, #95492 ID: 200506-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= SpamAssassin and Vipul's Razor are vulnerable to a Denial of Service attack when handling certain malformed messages. Background ========= SpamAssassin is an extensible email filter which is used to identify junk email. Vipul's Razor is a client for a distributed, collaborative spam detection and filtering network. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 mail-filter/spamassassin < 3.0.4 > = 3.0.4 < 3.0.1 2 mail-filter/razor < 2.71 > = 2.71 ------------------------------------------------------------------- 2 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== SpamAssassin and Vipul's Razor contain a Denial of Service vulnerability when handling special misformatted long message headers. Impact ===== By sending a specially crafted message an attacker could cause a Denial of Service attack against the SpamAssassin/Vipul's Razorserver. Workaround ========= There is no known workaround at this time. Resolution ========= All SpamAssassin users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =mail-filter/spamassassin-3.0.4" All Vipul's Razor users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =mail-filter/razor-2.71" References ========= [ 1 ] CAN-2005-1266 https://www.cve.org/CVERecord?id=CVE-CAN-2005-1266 [ 2 ] SpamAssassin Announcement https://lists.apache.org/thread/%
Get the latest Linux and open source security news straight to your inbox.