CVE Vulnerabilities

CVE-2006-2447

Published: Jun 06, 2006 | Modified: Oct 18, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly handled when invoking spamd with the virtual pop username.

Affected Software

Name Vendor Start Version End Version
Spamassassin Apache 3.1.0 (including) 3.1.0 (including)
Spamassassin Apache 3.1.1 (including) 3.1.1 (including)
Spamassassin Apache 3.1.2 (including) 3.1.2 (including)
Red Hat Enterprise Linux 4 RedHat spamassassin-0:3.0.6-1.el4 *
Spamassassin Ubuntu dapper *
Spamassassin Ubuntu devel *
Spamassassin Ubuntu edgy *
Spamassassin Ubuntu feisty *

References