<title>SpamAssassin 3, Vipul's Razor: Denial of Service vulnerability</title>
SpamAssassin and Vipul's Razor are vulnerable to a Denial of Service attack
when handling certain malformed messages.
SpamAssassin, Vipul's Razor
<announced>June 21, 2005</announced>
<revised>May 22, 2006: 03</revised>
spamassassin
unaffected range: >= 3.0.4
unaffected range: < 3.0.1
vulnerable range: < 3.0.4
razor
unaffected range: >= 2.74
vulnerable range: < 2.74
SpamAssassin is an extensible email filter which is used to identify
junk email. Vipul's Razor is a client for a distributed, collaborative
spam detection and filtering network.
SpamAssassin and Vipul's Razor contain a Denial of Service
vulnerability when handling special misformatted long message headers.
Impact:
By sending a specially crafted message an attacker could cause a Denial
of Service attack against the SpamAssassin/Vipul's Razor server.
There is no known workaround at this time.
All SpamAssassin users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose &quot;&gt;=mail-filter/spamassassin-3.0.4&quot;</code>
All Vipul's Razor users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose &quot;&gt;=mail-filter/razor-2.74&quot;</code>
<uri link="">CAN-2005-1266</uri>
<uri link="">CVE-2005-2024</uri>
<uri link="">SpamAssassin Announcement</uri>
<uri link=";forum_id=4259">Vipul's Razor Announcement</uri>
