SpamAssassin 3.1.x, 3.2.0, and 3.2.1 before 20070611, when running as root in unusual configurations using vpopmail or virtual users, allows local users to cause a denial of service (corrupt arbitrary files) via a symlink attack on a file that is used by spamd.
CVSS Details
- CVSS 3.1 Base Score: 3.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade spamassassin | Jul 30, 2024 | Jun 11, 2007 |
| Freebsd | — | Upgrade p5-Mail-SpamAssassin | Dec 10, 2025 | Jun 18, 2007 |
| Oracle_linux | — | Upgrade spamassassin | Oct 16, 2024 | Jun 11, 2007 |
| Suse | — | Upgrade spamassassinUpgrade perl-spamassassin | Aug 9, 2024 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub