CVE-2005-1266
published 2005-06-15CVE-2005-1266: Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long…
PriorityP418medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
8.35%
94.3th percentile
Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header without any boundaries.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | spamassassin | — | — |
| apache | spamassassin | — | — |
| apache | spamassassin | — | — |
| apache | spamassassin | >= 0 < 3.0.4-1 | 3.0.4-1 |
| apache | spamassassin | >= 0 < 3.0.4-1 | 3.0.4-1 |
| apache | spamassassin | >= 0 < 3.0.4-1 | 3.0.4-1 |
| apache | spamassassin | >= 0 < 3.0.4-1 | 3.0.4-1 |
| debian | spamassassin | < spamassassin 3.0.4-1 (bookworm) | spamassassin 3.0.4-1 (bookworm) |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8vfq-99xj-3qjx: Apache SpamAssassin 3
ghsa_unreviewed·2022-05-01
CVE-2005-1266 [MEDIUM] GHSA-8vfq-99xj-3qjx: Apache SpamAssassin 3
Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header without any boundaries.
OSV
CVE-2005-1266: Apache SpamAssassin 3
osv·2005-06-15·CVSS 5.0
CVE-2005-1266 [MEDIUM] CVE-2005-1266: Apache SpamAssassin 3
Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header without any boundaries.
Red Hat
security flaw
vendor_redhat·2005-06-15·CVSS 5.0
CVE-2005-1266 [MEDIUM] security flaw
security flaw
Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header without any boundaries.
Debian
CVE-2005-1266: spamassassin - Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a d...
vendor_debian·2005·CVSS 5.0
CVE-2005-1266 [MEDIUM] CVE-2005-1266: spamassassin - Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a d...
Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header without any boundaries.
Scope: local
bookworm: resolved (fixed in 3.0.4-1)
bullseye: resolved (fixed in 3.0.4-1)
forky: resolved (fixed in 3.0.4-1)
sid: resolved (fixed in 3.0.4-1)
trixie: resolved (fixed in 3.0.4-1)
No detection rules found.
No public exploits indexed.
http://bugs.gentoo.org/show_bug.cgi?id=94722http://mail-archives.apache.org/mod_mbox/spamassassin-announce/200506.mbox/%3c17072.35054.586017.822288%40proton.pathname.com%3ehttp://security.gentoo.org/glsa/glsa-200506-17.xmlhttp://www.debian.org/security/2005/dsa-736http://www.mandriva.com/security/advisories?name=MDKSA-2005:106http://www.redhat.com/support/errata/RHSA-2005-498.htmlhttp://www.securityfocus.com/bid/13978http://www.vuxml.org/freebsd/cc4ce06b-e01c-11d9-a8bd-000cf18bbe54.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10901http://bugs.gentoo.org/show_bug.cgi?id=94722http://mail-archives.apache.org/mod_mbox/spamassassin-announce/200506.mbox/%3c17072.35054.586017.822288%40proton.pathname.com%3ehttp://security.gentoo.org/glsa/glsa-200506-17.xmlhttp://www.debian.org/security/2005/dsa-736http://www.mandriva.com/security/advisories?name=MDKSA-2005:106http://www.redhat.com/support/errata/RHSA-2005-498.htmlhttp://www.securityfocus.com/bid/13978http://www.vuxml.org/freebsd/cc4ce06b-e01c-11d9-a8bd-000cf18bbe54.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10901
2005-06-15
Published