PT-2006-3405 · Apache+2 · Spamassassin+2

Publicado

2006-06-06

·

Atualizado

2018-10-18

·

CVE-2006-2447

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SpamAssassin versions prior to 3.1.3
Description The issue allows remote attackers to execute arbitrary commands via a crafted message that is not properly handled when invoking spamd with the virtual pop username, specifically when running with vpopmail and the paranoid (-P) switch.
Recommendations For versions prior to 3.1.3, update to version 3.1.3 or later to resolve the issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-2447
DSA-1090-1
RHSA-2006:0543
RHSA-2006_0543

Produtos afetados

Red Hat
Spamassassin
Vpopmail