Joined: 12 May 2004
|Posted: Fri Mar 02, 2007 2:26 am Post subject: [ GLSA 200703-02 ] SpamAssassin: Long URI Denial of Service
|Gentoo Linux Security Advisory
Title: SpamAssassin: Long URI Denial of Service (GLSA 200703-02)
Date: March 02, 2007
SpamAssassin is vulnerable to a Denial of Service attack.
SpamAssassin is an extensible email filter used to identify junk email.
Vulnerable: < 3.1.8
Unaffected: >= 3.1.8
Architectures: All supported architectures
SpamAssassin does not correctly handle very long URIs when scanning emails.
An attacker could cause SpamAssassin to consume large amounts of CPU and memory resources by sending one or more emails containing very long URIs.
There is no known workaround at this time.
All SpamAssassin users should upgrade to the latest version.
|# emerge --sync
# emerge --ask --oneshot --verbose ">=mail-filter/spamassassin-3.1.8"