First published: Fri Feb 16 2007(Updated: )
Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache SpamAssassin | =3.0.4 | |
Apache SpamAssassin | =3.0.3 | |
Apache SpamAssassin | =3.1.0 | |
Apache SpamAssassin | =3.0.1 | |
Apache SpamAssassin | <=3.1.7 | |
Apache SpamAssassin | =3.1.2 | |
Apache SpamAssassin | =3.0.2 | |
Apache SpamAssassin | =3.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0451 is classified as a denial of service vulnerability due to massive memory usage caused by long URLs in malformed HTML.
To fix CVE-2007-0451, upgrade Apache SpamAssassin to version 3.1.8 or later.
CVE-2007-0451 affects Apache SpamAssassin versions 3.0.1 through 3.1.7 and specific earlier versions.
Yes, CVE-2007-0451 can be exploited remotely by sending specially crafted long URLs.
Symptoms of exploitation of CVE-2007-0451 include significant memory usage and possible service disruption.