|
Family: Debian Local Security Checks --> Category: infos
[DSA736] DSA-736-1 spamassassin Vulnerability Scan
Vulnerability Scan Summary DSA-736-1 spamassassin
Detailed Explanation for this Vulnerability Test
A vulnerability was recently found in the way that SpamAssassin parses
certain email headers. This vulnerability could cause SpamAssassin to
consume a large number of CPU cycles when processing messages containing
these headers, leading to a potential denial of service (DOS) attack.
The version of SpamAssassin in the old stable distribution (woody) is
not vulnerable.
For the stable distribution (sarge), this problem has been fixed in
version 3.0.3-2. Note that packages are not yet ready for certain
architectures
these will be released as they become available.
For the unstable distribution (sid), this problem has been fixed in
version 3.0.4-1.
We recommend that you upgrade your sarge or sid spamassassin package.
Solution : http://www.debian.org/security/2005/dsa-736
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|