Denial of Service Vulnerability in Apache SpamAssassin by The Apache Software Foundation
CVE-2005-1266
Currently unrated
Summary
Apache SpamAssassin versions 3.0.1, 3.0.2, and 3.0.3 exhibit a vulnerability that can be exploited by remote attackers to create a denial of service condition. This is achieved through the use of a specially crafted message containing an excessively long Content-Type header. The vulnerability can lead to increased CPU consumption and performance degradation, effectively slowing down the service and disrupting email filtering operations.
References
EPSS Score
5% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved