CVE Vulnerabilities

CVE-2006-2447

Published: Jun 06, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly handled when invoking spamd with the virtual pop username.

Affected Software

NameVendorStart VersionEnd Version
SpamassassinApache3.1.0 (including)3.1.0 (including)
SpamassassinApache3.1.1 (including)3.1.1 (including)
SpamassassinApache3.1.2 (including)3.1.2 (including)
Red Hat Enterprise Linux 4RedHatspamassassin-0:3.0.6-1.el4*
SpamassassinUbuntudapper*
SpamassassinUbuntudevel*
SpamassassinUbuntuedgy*
SpamassassinUbuntufeisty*

References