vendor:
SpamAssassin
by:
patrick
7.5
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: SpamAssassin
Affected Version From: Not specified
Affected Version To: v3.1.2
Patch Exists: NO
Related CWE: CVE-2006-2447
CPE: a:spamassassin:spamassassin
Platforms Tested: unix
2006
SpamAssassin spamd Remote Command Execution
This module exploits a flaw in the SpamAssassin spamd service by specifying a malicious vpopmail User header, when running with vpopmail and paranoid modes enabled (non-default). Versions prior to v3.1.3 are vulnerable
Mitigation:
Upgrade to version v3.1.3 or later