SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly handled when invoking spamd with the virtual pop username.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade spamassassin | Jul 30, 2024 | Jun 6, 2006 |
| Gentoo Linux | — | Upgrade mail-filter/spamassassin. | Oct 30, 2017 | Jun 6, 2006 |
| Suse | — | Upgrade perl-spamassassin | Dec 12, 2013 | Jun 6, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub