Vulnerability Description
MDaemon Email Server 19 through 20.0.1 skips SpamAssassin checks by default for e-mail messages larger than 2 MB (and limits checks to 10 MB even with special configuration), which is arguably inconsistent with currently popular message sizes. This might interfere with risk management for malicious e-mail, if a customer deploys a server with sufficient resources to scan large messages.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Altn | Mdaemon Email Server | 19 |
Related Weaknesses (CWE)
References
- http://lists.altn.com/WebX/.59862f3cVendor Advisory
- http://lists.altn.com/WebX/.59862f3cVendor Advisory
FAQ
What is CVE-2019-13612?
CVE-2019-13612 is a vulnerability with a CVSS score of 7.5 (HIGH). MDaemon Email Server 19 through 20.0.1 skips SpamAssassin checks by default for e-mail messages larger than 2 MB (and limits checks to 10 MB even with special configuration), which is arguably inconsi...
How severe is CVE-2019-13612?
CVE-2019-13612 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-13612?
Check the references section above for vendor advisories and patch information. Affected products include: Altn Mdaemon Email Server.