Vulnerability Description
SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Spamassassin | 3.0.4 |
References
- http://issues.apache.org/SpamAssassin/show_bug.cgi?id=4570
- http://lwn.net/Alerts/159300/PatchVendor Advisory
- http://osvdb.org/11581
- http://secunia.com/advisories/17386/
- http://secunia.com/advisories/17518/
- http://secunia.com/advisories/17626/
- http://secunia.com/advisories/17666/
- http://secunia.com/advisories/17877
- http://secunia.com/advisories/19158
- http://www.gossamer-threads.com/lists/spamassassin/devel/62649PatchVendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:221
- http://www.novell.com/linux/security/advisories/2005_27_sr.html
- http://www.redhat.com/support/errata/RHSA-2006-0129.html
- http://www.securityfocus.com/bid/15373
- http://www.vupen.com/english/advisories/2005/2364
FAQ
What is CVE-2005-3351?
CVE-2005-3351 is a vulnerability with a CVSS score of 5.0 (MEDIUM). SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl.
How severe is CVE-2005-3351?
CVE-2005-3351 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-3351?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Spamassassin.