Denial of Service Vulnerability in Apache SpamAssassin by The Apache Software Foundation
CVE-2005-1266

Currently unrated

Key Information:

Vendor
Apache
Vendor
CVE Published:
15 June 2005

Summary

Apache SpamAssassin versions 3.0.1, 3.0.2, and 3.0.3 exhibit a vulnerability that can be exploited by remote attackers to create a denial of service condition. This is achieved through the use of a specially crafted message containing an excessively long Content-Type header. The vulnerability can lead to increased CPU consumption and performance degradation, effectively slowing down the service and disrupting email filtering operations.

References

EPSS Score

5% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.