Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Производитель ПО
Наименование ПО
spamassassin
(Unknown)
Описание
Apache SpamAssassin позволяет злоумышленникам, действующим удаленно, вызвать отказ в обслуживании, используя длинные URL в искаженном HTML, из-за который возникает чрезмерное потребление ресурсов памяти.
Как исправить
Для устранения уязвимости необходимо установить последнюю версию продукта, соответствующую используемой платформе. Необходимую информацию можно получить по адресу:
http://spamassassin.apache.org/
http://spamassassin.apache.org/
Ссылки
http://svn.apache.org/repos/asf/spamassassin/branches/3.1/build/announcements/3.1.8.txt
FEDORA (FEDORA-2007-242): http://fedoranews.org/cms/node/2657
FEDORA (FEDORA-2007-241): http://fedoranews.org/cms/node/2659
FRSIRT (ADV-2007-0628): http://www.frsirt.com/english/advisories/2007/0628
BID (22584): http://www.securityfocus.com/bid/22584
http://spamassassin.apache.org/advisories/cve-2007-0451.txt
https://issues.rpath.com/browse/RPL-1073
GENTOO (GLSA-200703-02): http://security.gentoo.org/glsa/glsa-200703-02.xml
MANDRIVA (MDKSA-2007:049): http://www.mandriva.com/security/advisories?name=MDKSA-2007:049
REDHAT (RHSA-2007:0074): http://rhn.redhat.com/errata/RHSA-2007-0074.html
REDHAT (RHSA-2007:0075): http://www.redhat.com/support/errata/RHSA-2007-0075.html
SECTRACK (1017666): http://www.securitytracker.com/id?1017666
XF (spamassassin-url-dos(32536)): http://xforce.iss.net/xforce/xfdb/32536
SUSE (SUSE-SR:2007:006): http://www.novell.com/linux/security/advisories/2007_6_sr.html
FEDORA (FEDORA-2007-242): http://fedoranews.org/cms/node/2657
FEDORA (FEDORA-2007-241): http://fedoranews.org/cms/node/2659
FRSIRT (ADV-2007-0628): http://www.frsirt.com/english/advisories/2007/0628
BID (22584): http://www.securityfocus.com/bid/22584
http://spamassassin.apache.org/advisories/cve-2007-0451.txt
https://issues.rpath.com/browse/RPL-1073
GENTOO (GLSA-200703-02): http://security.gentoo.org/glsa/glsa-200703-02.xml
MANDRIVA (MDKSA-2007:049): http://www.mandriva.com/security/advisories?name=MDKSA-2007:049
REDHAT (RHSA-2007:0074): http://rhn.redhat.com/errata/RHSA-2007-0074.html
REDHAT (RHSA-2007:0075): http://www.redhat.com/support/errata/RHSA-2007-0075.html
SECTRACK (1017666): http://www.securitytracker.com/id?1017666
XF (spamassassin-url-dos(32536)): http://xforce.iss.net/xforce/xfdb/32536
SUSE (SUSE-SR:2007:006): http://www.novell.com/linux/security/advisories/2007_6_sr.html