Back to search
CVE-2006-2447
Published: Jun 6, 2006
Modified: Aug 7, 2024
PUBLISHED
Description
SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly handled when invoking spamd with the virtual pop username.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20482
third-party-advisory
x_refsource_SECUNIA
20060607 rPSA-2006-0096-1 spamassassin
mailing-list
x_refsource_BUGTRAQ
oval:org.mitre.oval:def:9184
vdb-entry
signature
x_refsource_OVAL
2006-0034
vendor-advisory
x_refsource_TRUSTIX
GLSA-200606-09
vendor-advisory
x_refsource_GENTOO
20692
third-party-advisory
x_refsource_SECUNIA
20566
third-party-advisory
x_refsource_SECUNIA
18290
vdb-entry
x_refsource_BID
20430
third-party-advisory
x_refsource_SECUNIA
RHSA-2006:0543
vendor-advisory
x_refsource_REDHAT
ADV-2006-2148
vdb-entry
x_refsource_VUPEN
20531
third-party-advisory
x_refsource_SECUNIA
1016230
vdb-entry
x_refsource_SECTRACK
DSA-1090
vendor-advisory
x_refsource_DEBIAN
spamassassin-spamd-command-execution(27008)
vdb-entry
x_refsource_XF
20443
third-party-advisory
x_refsource_SECUNIA
1016235
vdb-entry
x_refsource_SECTRACK
MDKSA-2006:103
vendor-advisory
x_refsource_MANDRIVA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now