Short Name |
SMTP:SPAMASS-DOS |
---|---|
Severity |
Medium |
Recommended |
No |
Category |
SMTP |
Keywords |
SpamAssassin Content-Type Denial of Service |
Release Date |
2005/07/26 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects a malformed e-mail that can trigger a denial-of-service condition within the SpamAssassin daemon. This attack could be used to disable the spam filtering system of a mail server.
SpamAssassin is prone to a remote denial-of-service vulnerability because the application fails to properly handle overly long email headers. Further details regarding this vulnerability are currently not available. This BID will be updated as more information is disclosed. An attacker may cause SpamAssassin to take inordinate amounts of time to check a specially crafted email message. By sending many malicious messages, the attacker may be able to cause extremely large delays in email delivery, denying service to legitimate users.