Security Advisory

CVE-2006-2447

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2006-06-06 21:00:00
Last updated 2024-08-07 17:51:04
Assigner redhat
State PUBLISHED

Description

SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly handled when invoking spamd with the virtual pop username.