Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 112063 - mail-filter/spamassassin Long Message Header Denial of Service (CVE-2005-3351)
Summary: mail-filter/spamassassin Long Message Header Denial of Service (CVE-2005-3351)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/17386/
Whiteboard: B3? [noglsa] jaervosz
Keywords:
Depends on:
Blocks:
 
Reported: 2005-11-10 02:48 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2019-12-01 21:29 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-11-10 02:48:56 UTC
Description: 
A vulnerability has been reported in SpamAssassin, which can be exploited by 
malicious people to cause a DoS (Denial of Service). 
  
 The vulnerability is caused due to the use of an inefficient regular 
expression in "/SpamAssassin/Message.pm" to parse email headers. This can 
cause perl to crash when it runs out of stack space and can be exploited via a 
malicious email that contains a large number of recipients. 
  
 The vulnerability has been reported in version 3.0.4. Prior versions may also 
be affected. 
 
Solution: 
Update to version 3.1.0. 
 http://spamassassin.apache.org/downloads.cgi?update=200509141634 
 
Provided and/or discovered by: 
Irina and Mark Martinec. 
 
Original Advisory: 
http://issues.apache.org/SpamAssassin/show_bug.cgi?id=4570
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-11-10 02:52:14 UTC
Perl please provide an updated ebuild. 
  
AFAIR bumping works fine when you remove references to the STATISTICS sets.  
  
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-11-10 03:01:52 UTC
This also fixes bug #72109 for me. 
Comment 3 Sebastien Brossier 2005-11-10 04:24:22 UTC
ebuild for SpamAssassin 3.1.0 :
http://bugs.gentoo.org/show_bug.cgi?id=106028
Comment 4 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-11-10 06:48:18 UTC
Unless spamd crashes I'm not sure this is really a security issue though. Perl 
please advise. 
Comment 5 Michael Cummings (RETIRED) gentoo-dev 2005-11-12 15:04:22 UTC
3.1.0 went into the tree yesterday. (Of course, I'm still cleaning up my rusty
ebuild making skills)
Comment 6 Thierry Carrez (RETIRED) gentoo-dev 2005-11-13 10:19:26 UTC
Raches please test and mark 3.1.0 stable...

Target keywords for 3.1.0 :
KEYWORDS="alpha amd64 hppa ia64 ppc ppc64 sparc x86 mips"
Comment 7 Jason Wever (RETIRED) gentoo-dev 2005-11-13 11:04:58 UTC
Tested against sample email in spamassassin bugzilla bug.  Everything checks
out.  Stable on SPARC.
Comment 8 Fernando J. Pereda (RETIRED) gentoo-dev 2005-11-13 11:48:22 UTC
I hereby bless you with the alpha keyword.

Cheers,
Ferdy
Comment 9 Mark Loeser (RETIRED) gentoo-dev 2005-11-13 13:54:18 UTC
Stable on x86
Comment 10 Markus Rothe (RETIRED) gentoo-dev 2005-11-14 05:59:55 UTC
stable on ppc64 
Comment 11 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2005-11-14 13:32:02 UTC
Stable on ppc and hppa.
Comment 12 Homer Parker (RETIRED) gentoo-dev 2005-11-16 16:48:41 UTC
amd64 happy
Comment 13 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-11-16 22:08:53 UTC
This one is ready for GLSA decision. Until someone verify that spamd is 
affected I vote NO. 
Comment 14 Thierry Carrez (RETIRED) gentoo-dev 2005-11-17 01:43:33 UTC
From http://issues.apache.org/SpamAssassin/show_bug.cgi?id=4570#c21 :

I'm not sure if it's possible to actually use this to cause a practical DoS,
btw.  it would be possible to get a message passed as nonspam (through scanner
failure), but the scanner should recover the dead child process immediately for
later scans; spamd is resilient in the face of the Mail::SpamAssassin classes
blowing up.

So I vote NO too, and closing.
Comment 15 Henrik Brix Andersen 2005-11-21 09:00:07 UTC
Please see bug #113021 - mail-filter/spamassassin-3.1.0, which seems to have
been rushed to stable due to this bug, misses an RDEPEND.
Comment 16 Michael Cummings (RETIRED) gentoo-dev 2005-11-21 09:52:02 UTC
(In reply to comment #15)
> Please see bug #113021 - mail-filter/spamassassin-3.1.0, which seems to have
> been rushed to stable due to this bug, misses an RDEPEND.

Fixed and in portage