Description
Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."
CVSS vector
AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9Confidentiality: None
Integrity: None
Affected Packages2 packages
🔴Vulnerability Details
3GHSAGHSA-q35m-3hwc-qp9v: Apache SpamAssassin before 3↗2022-05-01 ▶ OSVCVE-2007-0451: Apache SpamAssassin before 3↗2007-02-16 ▶ CVEListCVE-2007-0451: Apache SpamAssassin before 3↗2007-02-16 ▶ 📋Vendor Advisories
2DebianCVE-2007-0451: spamassassin - Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of se...↗2007 ▶ 💬Community
3BugzillaCVE-2007-0451 security flaw↗2018-08-16 ▶ BugzillaCVE-2007-0451 Spamassassin DoS↗2007-02-13 ▶ BugzillaCVE-2007-0451 Spamassassin DoS↗2007-02-13 ▶