CVE-2005-3351
published 2005-11-20CVE-2005-3351: SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
7.26%
93.6th percentile
SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | spamassassin | — | — |
| apache | spamassassin | >= 0 < 3.1.0a-1 | 3.1.0a-1 |
| apache | spamassassin | >= 0 < 3.1.0a-1 | 3.1.0a-1 |
| apache | spamassassin | >= 0 < 3.1.0a-1 | 3.1.0a-1 |
| apache | spamassassin | >= 0 < 3.1.0a-1 | 3.1.0a-1 |
| debian | spamassassin | < spamassassin 3.1.0a-1 (bookworm) | spamassassin 3.1.0a-1 (bookworm) |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m2fg-q836-9pmq: SpamAssassin 3
ghsa_unreviewed·2022-05-01
CVE-2005-3351 [MEDIUM] GHSA-m2fg-q836-9pmq: SpamAssassin 3
SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl.
OSV
CVE-2005-3351: SpamAssassin 3
osv·2005-11-20·CVSS 5.0
CVE-2005-3351 [MEDIUM] CVE-2005-3351: SpamAssassin 3
SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl.
Red Hat
security flaw
vendor_redhat·2005-09-05·CVSS 5.0
CVE-2005-3351 [MEDIUM] security flaw
security flaw
SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl.
Debian
CVE-2005-3351: spamassassin - SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with ...
vendor_debian·2005·CVSS 5.0
CVE-2005-3351 [MEDIUM] CVE-2005-3351: spamassassin - SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with ...
SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl.
Scope: local
bookworm: resolved (fixed in 3.1.0a-1)
bullseye: resolved (fixed in 3.1.0a-1)
forky: resolved (fixed in 3.1.0a-1)
sid: resolved (fixed in 3.1.0a-1)
trixie: resolved (fixed in 3.1.0a-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-3351 security flaw
bugzilla·2018-08-16·CVSS 5.0
CVE-2005-3351 [MEDIUM] CVE-2005-3351 security flaw
CVE-2005-3351 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl.
Bugzilla
CVE-2005-3351 Upgrade to spamassassin-3.0.5
bugzilla·2005-10-20·CVSS 5.0
CVE-2005-3351 [MEDIUM] CVE-2005-3351 Upgrade to spamassassin-3.0.5
CVE-2005-3351 Upgrade to spamassassin-3.0.5
RHEL4U3 should upgrade to the (not yet released) spamassassin-3.0.5 in order to
fix multiple denial of service issues and many bugs. This maintenance release
improves both runtime safety and spam detection accuracy.
Justification
- Spamassassin must constantly evolve in an arms race with hostile entities on
the Internet.
- Thus it must upgrade periodically in order to remain useful.
- 3.x retains API/ABI compatibiltiy with 3rd party software [1]
- No QA resources are required. Warren will handle all testing.
- Low risk changes due to conservative upstream development policy
Most Important Bugs
- Bug #161785 where our init.d service script fails to restart the spamassassin
service because killing the previous spamd failed.
- Multiple Denial of
http://issues.apache.org/SpamAssassin/show_bug.cgi?id=4570http://lwn.net/Alerts/159300/http://osvdb.org/11581http://secunia.com/advisories/17386/http://secunia.com/advisories/17518/http://secunia.com/advisories/17626/http://secunia.com/advisories/17666/http://secunia.com/advisories/17877http://secunia.com/advisories/19158http://www.gossamer-threads.com/lists/spamassassin/devel/62649http://www.mandriva.com/security/advisories?name=MDKSA-2005:221http://www.novell.com/linux/security/advisories/2005_27_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0129.htmlhttp://www.securityfocus.com/bid/15373http://www.vupen.com/english/advisories/2005/2364https://exchange.xforce.ibmcloud.com/vulnerabilities/23048https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11125http://issues.apache.org/SpamAssassin/show_bug.cgi?id=4570http://lwn.net/Alerts/159300/http://osvdb.org/11581http://secunia.com/advisories/17386/http://secunia.com/advisories/17518/http://secunia.com/advisories/17626/http://secunia.com/advisories/17666/http://secunia.com/advisories/17877http://secunia.com/advisories/19158http://www.gossamer-threads.com/lists/spamassassin/devel/62649http://www.mandriva.com/security/advisories?name=MDKSA-2005:221http://www.novell.com/linux/security/advisories/2005_27_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0129.htmlhttp://www.securityfocus.com/bid/15373http://www.vupen.com/english/advisories/2005/2364https://exchange.xforce.ibmcloud.com/vulnerabilities/23048https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11125
2005-11-20
Published