First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 112063
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 112063 depends on: Show dependency tree
Show dependency graph
Bug 112063 blocks:

Additional Comments: (this is where you put emerge --info)







View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-11-10 02:48 0000
Description: 
A vulnerability has been reported in SpamAssassin, which can be exploited by 
malicious people to cause a DoS (Denial of Service). 
  
 The vulnerability is caused due to the use of an inefficient regular 
expression in "/SpamAssassin/Message.pm" to parse email headers. This can 
cause perl to crash when it runs out of stack space and can be exploited via a 
malicious email that contains a large number of recipients. 
  
 The vulnerability has been reported in version 3.0.4. Prior versions may also 
be affected. 
 
Solution: 
Update to version 3.1.0. 
 http://spamassassin.apache.org/downloads.cgi?update=200509141634 
 
Provided and/or discovered by: 
Irina and Mark Martinec. 
 
Original Advisory: 
http://issues.apache.org/SpamAssassin/show_bug.cgi?id=4570

------- Comment #1 From Sune Kloppenborg Jeppesen 2005-11-10 02:52:14 0000 -------
Perl please provide an updated ebuild. 
  
AFAIR bumping works fine when you remove references to the STATISTICS sets.  
  

------- Comment #2 From Sune Kloppenborg Jeppesen 2005-11-10 03:01:52 0000 -------
This also fixes bug #72109 for me. 

------- Comment #3 From Sebastien Brossier 2005-11-10 04:24:22 0000 -------
ebuild for SpamAssassin 3.1.0 :
http://bugs.gentoo.org/show_bug.cgi?id=106028

------- Comment #4 From Sune Kloppenborg Jeppesen 2005-11-10 06:48:18 0000 -------
Unless spamd crashes I'm not sure this is really a security issue though. Perl 
please advise. 

------- Comment #5 From Michael Cummings (RETIRED) 2005-11-12 15:04:22 0000 -------
3.1.0 went into the tree yesterday. (Of course, I'm still cleaning up my rusty
ebuild making skills)

------- Comment #6 From Thierry Carrez (RETIRED) 2005-11-13 10:19:26 0000 -------
Raches please test and mark 3.1.0 stable...

Target keywords for 3.1.0 :
KEYWORDS="alpha amd64 hppa ia64 ppc ppc64 sparc x86 mips"

------- Comment #7 From Jason Wever (RETIRED) 2005-11-13 11:04:58 0000 -------
Tested against sample email in spamassassin bugzilla bug.  Everything checks
out.  Stable on SPARC.

------- Comment #8 From Fernando J. Pereda 2005-11-13 11:48:22 0000 -------
I hereby bless you with the alpha keyword.

Cheers,
Ferdy

------- Comment #9 From Mark Loeser 2005-11-13 13:54:18 0000 -------
Stable on x86

------- Comment #10 From Markus Rothe 2005-11-14 05:59:55 0000 -------
stable on ppc64 

------- Comment #11 From Michael Hanselmann (hansmi) (RETIRED) 2005-11-14 13:32:02 0000 -------
Stable on ppc and hppa.

------- Comment #12 From Homer Parker 2005-11-16 16:48:41 0000 -------
amd64 happy

------- Comment #13 From Sune Kloppenborg Jeppesen 2005-11-16 22:08:53 0000 -------
This one is ready for GLSA decision. Until someone verify that spamd is 
affected I vote NO. 

------- Comment #14 From Thierry Carrez (RETIRED) 2005-11-17 01:43:33 0000 -------
From http://issues.apache.org/SpamAssassin/show_bug.cgi?id=4570#c21 :

I'm not sure if it's possible to actually use this to cause a practical DoS,
btw.  it would be possible to get a message passed as nonspam (through scanner
failure), but the scanner should recover the dead child process immediately for
later scans; spamd is resilient in the face of the Mail::SpamAssassin classes
blowing up.

So I vote NO too, and closing.

------- Comment #15 From Henrik Brix Andersen 2005-11-21 09:00:07 0000 -------
Please see bug #113021 - mail-filter/spamassassin-3.1.0, which seems to have
been rushed to stable due to this bug, misses an RDEPEND.

------- Comment #16 From Michael Cummings (RETIRED) 2005-11-21 09:52:02 0000 -------
(In reply to comment #15)
> Please see bug #113021 - mail-filter/spamassassin-3.1.0, which seems to have
> been rushed to stable due to this bug, misses an RDEPEND.

Fixed and in portage

First Last Prev Next    No search results available      Search page      Enter new bug