Total vulnerabilities in the database
SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly handled when invoking spamd with the virtual pop username.
Software | From | Fixed in |
---|---|---|
apache / spamassassin | 3.1.0 | 3.1.0.x |
apache / spamassassin | 3.1.2 | 3.1.2.x |
apache / spamassassin | 3.1.1 | 3.1.1.x |