Family: Debian Local Security Checks --> Category: infos
[DSA736] DSA-736-1 spamassassin Vulnerability Scan
Vulnerability Scan Summary
Detailed Explanation for this Vulnerability Test
A vulnerability was recently found in the way that SpamAssassin parses
certain email headers. This vulnerability could cause SpamAssassin to
consume a large number of CPU cycles when processing messages containing
these headers, leading to a potential denial of service (DOS) attack.
The version of SpamAssassin in the old stable distribution (woody) is
For the stable distribution (sarge), this problem has been fixed in
version 3.0.3-2. Note that packages are not yet ready for certain
these will be released as they become available.
For the unstable distribution (sid), this problem has been fixed in
We recommend that you upgrade your sarge or sid spamassassin package.
Solution : http://www.debian.org/security/2005/dsa-736
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.