[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2007-0451Date: (C)2007-02-16   (M)2023-12-22


Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
SECTRACK-1017666
BID-22584
SECUNIA-24197
SECUNIA-24200
SECUNIA-24250
SECUNIA-24256
SECUNIA-24265
SECUNIA-24307
SECUNIA-24889
OSVDB-33207
ADV-2007-0628
FEDORA-2007-241
FEDORA-2007-242
GLSA-200703-02
MDKSA-2007:049
RHSA-2007:0074
RHSA-2007:0075
SUSE-SR:2007:006
http://spamassassin.apache.org/advisories/cve-2007-0451.txt
http://svn.apache.org/repos/asf/spamassassin/branches/3.1/build/announcements/3.1.8.txt
https://issues.rpath.com/browse/RPL-1073
oval:org.mitre.oval:def:10018
spamassassin-url-dos(32536)

CPE    8
cpe:/a:apache:spamassassin:3.1.1
cpe:/a:apache:spamassassin:3.0.1
cpe:/a:apache:spamassassin:3.1.0
cpe:/a:apache:spamassassin:3.0.2
...
CWE    1
CWE-399

© SecPod Technologies