SMTP: SpamAssassin Content-Type Denial of Service

This signature detects a malformed e-mail that can trigger a denial-of-service condition within the SpamAssassin daemon. This attack could be used to disable the spam filtering system of a mail server.

Extended Description

SpamAssassin is prone to a remote denial-of-service vulnerability because the application fails to properly handle overly long email headers. Further details regarding this vulnerability are currently not available. This BID will be updated as more information is disclosed. An attacker may cause SpamAssassin to take inordinate amounts of time to check a specially crafted email message. By sending many malicious messages, the attacker may be able to cause extremely large delays in email delivery, denying service to legitimate users.

Affected Products

Mandriva linux_mandrake

Short Name
SMTP:SPAMASS-DOS
Severity
Minor
Recommended
False
Recommended Action
None
Category
SMTP
Keywords
CVE-2005-1266 Content-Type Denial Service SpamAssassin bid:13978 of
Release Date
07/26/2005
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

srx-branch-12.3

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx-12.3

vmx-19.3

srx-12.3

Sigpack Version
3727
False Positive
Unknown
Vendors

Red_hat

Spamassassin

Mandriva

Suse

Gentoo

CVSS Score

5.0

Found a potential security threat?