CVE Vulnerabilities

CVE-2007-2873

Published: Jun 11, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
1.9 LOW
AV:L/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

SpamAssassin 3.1.x, 3.2.0, and 3.2.1 before 20070611, when running as root in unusual configurations using vpopmail or virtual users, allows local users to cause a denial of service (corrupt arbitrary files) via a symlink attack on a file that is used by spamd.

Affected Software

NameVendorStart VersionEnd Version
SpamassassinSpamassassin3.1.0 (including)3.1.0 (including)
SpamassassinSpamassassin3.1.1 (including)3.1.1 (including)
SpamassassinSpamassassin3.1.2 (including)3.1.2 (including)
SpamassassinSpamassassin3.1.3 (including)3.1.3 (including)
SpamassassinSpamassassin3.1.4 (including)3.1.4 (including)
SpamassassinSpamassassin3.1.5 (including)3.1.5 (including)
SpamassassinSpamassassin3.1.6 (including)3.1.6 (including)
SpamassassinSpamassassin3.1.7 (including)3.1.7 (including)
SpamassassinSpamassassin3.1.8 (including)3.1.8 (including)
SpamassassinSpamassassin3.1.9 (including)3.1.9 (including)
SpamassassinSpamassassin3.2.0 (including)3.2.0 (including)
SpamassassinSpamassassin3.2.1 (including)3.2.1 (including)
Red Hat Enterprise Linux 4RedHatspamassassin-0:3.1.9-1.el4*
Red Hat Enterprise Linux 5RedHatspamassassin-0:3.1.9-1.el5*
SpamassassinUbuntudapper*
SpamassassinUbuntudevel*
SpamassassinUbuntuedgy*
SpamassassinUbuntufeisty*
SpamassassinUbuntugutsy*
SpamassassinUbuntuhardy*
SpamassassinUbuntuintrepid*
SpamassassinUbuntujaunty*
SpamassassinUbuntukarmic*

References