Remote Command Execution Vulnerability in SpamAssassin by Apache
CVE-2006-2447
Currently unrated
What is CVE-2006-2447?
A flaw in SpamAssassin prior to version 3.1.3 can lead to remote attackers executing arbitrary commands on the server. When running with vpopmail and the paranoid switch (-P), crafted email messages can exploit improper handling of the virtual pop user, leading to potential unauthorized command execution on the affected systems.