CVE-2005-3351

8 documents7 sources
Severity
5.0MEDIUM
EPSS
17.9%
top 4.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 20
Latest updateMay 1

Description

SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debianspamassassin< 3.1.0a-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-m2fg-q836-9pmq: SpamAssassin 32022-05-01
CVEList
CVE-2005-3351: SpamAssassin 32005-11-20
OSV
CVE-2005-3351: SpamAssassin 32005-11-20

📋Vendor Advisories

2
Red Hat
security flaw2005-09-05
Debian
CVE-2005-3351: spamassassin - SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with ...2005

💬Community

2
Bugzilla
CVE-2005-3351 security flaw2018-08-16
Bugzilla
CVE-2005-3351 Upgrade to spamassassin-3.0.52005-10-20