PT-2018-5980 · Apache+5 · Apache Spamassassin+5

Published

2018-09-17

·

Updated

2024-06-15

·

CVE-2017-15705

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions: Apache SpamAssassin versions prior to 3.4.2
Description: A denial of service issue exists due to the incorrect handling of certain unclosed tags in emails, leading to scan timeouts. This occurs because the HTML::Parser module used by Apache SpamAssassin does not properly handle the "text" event for poorly formed HTML, causing the object to be handled abnormally. The issue is believed to be related to a bug or design decision in HTML::Parser. There have been instances of this issue being exploited in the wild, although it is not thought to have been intentionally used for denial of service attacks. However, there is concern that it may be abused in the future.
Recommendations: For versions prior to 3.4.2, update to version 3.4.2 or later to resolve the issue. As a temporary workaround, consider restricting the parsing of HTML emails to minimize the risk of exploitation.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2985
ALT-PU-2018-2986
CESA-2018_2916
CVE-2017-15705
DLA-1578-1
ELSA-2018-2916
MGASA-2018-0425
OPENSUSE-SU-2019:1831-1
OPENSUSE-SU-2019_1831-1
OPENSUSE-SU-2024:11395-1
RHSA-2018:2916
RHSA-2018_2916
SUSE-SU-2019:1961-1
SUSE-SU-2019:2011-1
SUSE-SU-2019_1961-1
USN-3811-1
USN-3811-2

Affected Products

Alt Linux
Apache Spamassassin
Centos
Red Hat
Suse
Ubuntu