CVE-2019-13612: Input Validation
MDaemon Email Server 19 through 20.0.1 skips SpamAssassin checks by default for e-mail messages larger than 2 MB (and limits checks to 10 MB even with special configuration), which is arguably inconsistent with currently popular message sizes. This might interfere with risk management for malicious e-mail, if a customer deploys a server with sufficient resources to scan large messages.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-13612?
CVE-2019-13612 is a vulnerability that allows MDaemon Email Server 19 through 20.0.1 to skip SpamAssassin checks for e-mail messages larger than 2 MB.
What is the severity of CVE-2019-13612?
CVE-2019-13612 has a severity rating of 7.5 (high).
How does CVE-2019-13612 affect MDaemon Email Server?
CVE-2019-13612 affects MDaemon Email Server 19 through 20.0.1 by allowing it to skip SpamAssassin checks for large e-mail messages.
How can I mitigate the risk of CVE-2019-13612?
To mitigate the risk of CVE-2019-13612, you can update MDaemon Email Server to version 20.0.2 or later, which includes a fix for this vulnerability.
Where can I find more information about CVE-2019-13612?
You can find more information about CVE-2019-13612 at the following link: http://lists.altn.com/WebX/.59862f3c