SpamAssassin Long Message Header Denial of Service

A vulnerability has been reported in SpamAssassin, which can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to the use of an inefficient regular expression in “/SpamAssassin/Message.pm” to parse email headers. This can cause perl to crash when it runs out of stack space and can be exploited via a malicious email that contains a large number of recipients.

The vulnerability has been reported in version 3.0.4. Prior versions may also be affected.

Update to version 3.1.0.
Original advisory

Tags: , , , , , ,

Leave a Comment

Couldn't find your convert utility. Check that you have ImageMagick installed.