FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

p5-Mail-SpamAssassin -- long message header denial of service

Affected packages
p5-Mail-SpamAssassin < 3.1.0


VuXML ID 7f3fdef7-51d2-11da-8e93-0010dc4afb40
Discovery 2005-11-10
Entry 2005-11-10

A Secunia Advisory reports:

A vulnerability has been reported in SpamAssassin, which can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to the use of an inefficient regular expression in "/SpamAssassin/" to parse email headers. This can cause perl to crash when it runs out of stack space and can be exploited via a malicious email that contains a large number of recipients.