Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Gentoo: 200302-01 Critical: Mail-SpamAssassin Remote Code Execution Risk

gentoo
Calendar Grey February 2, 2003
Dist Gentoo Esm H88
Gentoo Linux Advisory 200302-01; Mail-SpamAssassin faces a vulnerability that could allow arbitrary code execution triggered by specially crafted emails.
An attacker may be able to execute arbitrary code by sending a specially crafted e-mail to a system using SpamAssassin's spamc program in BSMTP mode.

Summary


- --------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200302-01
- --------------------------------------------------------------------
DATE    : 2003-02-02 13:25 UTC

- --------------------------------------------------------------------
From advisory:
"Attacker may be able to execute arbitrary code by sending a specially crafted e-mail to a system using SpamAssassin's spamc program in BSMTP mode (-B option). Versions from 2.40 to 2.43 are affected."
Read the full advisory at http://marc.theaimsgroup.com/?l=bugtraq&m=104342896818777&w=2
SOLUTION
It is recommended that all Gentoo Linux users who are running dev-perl/Mail-SpamAssasin to Mail-SpamAssasin-2.44 as follows:
emerge sync emerge -u Mail-SpamAssasin emerge clean
- -------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at - --------------------------------------------------------------------

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
critical
Lowest
Low
Medium
High
Critical

PACKAGE : Mail-SpamAssasin
SUMMARY : arbitrary code execution
EXPLOIT : remote

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here