CVE-2006-2447
spamassassin - programming error
EPSS 74.7%
描述
SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly handled when invoking spamd with the virtual pop username.
如何修補 CVE-2006-2447
要修補 CVE-2006-2447,請將受影響套件升級到下列已修補版本。
- Debian/spamassassin—升級至 3.1.3-1 或更新版本
- Debian/spamassassin—升級至 3.0.3-2sarge1 或更新版本
CVE-2006-2447 正在被利用嗎?
可能 — EPSS 為 74.7%,屬於高被利用機率區間,建議優先修補。
受影響套件(2)
- from 0, < 3.1.3-1
- from 0, < 3.0.3-2sarge1