FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

p5-Mail-SpamAssassin -- long message header denial of service

Affected packages
p5-Mail-SpamAssassin < 3.1.0

Details

VuXML ID 7f3fdef7-51d2-11da-8e93-0010dc4afb40
Discovery 2005-11-10
Entry 2005-11-10

A Secunia Advisory reports:

A vulnerability has been reported in SpamAssassin, which can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to the use of an inefficient regular expression in "/SpamAssassin/Message.pm" to parse email headers. This can cause perl to crash when it runs out of stack space and can be exploited via a malicious email that contains a large number of recipients.

References

URL http://issues.apache.org/SpamAssassin/show_bug.cgi?id=4570
URL http://secunia.com/advisories/17386/