SpamProbe Remote Denial of Service Vulnerability
BID:6739
Info
SpamProbe Remote Denial of Service Vulnerability
| Bugtraq ID: | 6739 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 30 2003 12:00AM |
| Updated: | Jan 30 2003 12:00AM |
| Credit: | This vulnerability was announced in the product changelog. |
| Vulnerable: |
SpamProbe SpamProbe 0.8 a |
| Not Vulnerable: |
SpamProbe SpamProbe 0.8 b |
Discussion
SpamProbe Remote Denial of Service Vulnerability
A denial of service vulnerability exists in SpamProbe. It has been reported that emails containing newlines within HTML <href> tags may cause SpamProbe to crash. This occurs when parsing the tag with a regular expression.
This issue has been reported to occur on RedHat 8.0. It is not yet known whether SpamProbe is prone to this issue when running on other distributions or operating systems.
A denial of service vulnerability exists in SpamProbe. It has been reported that emails containing newlines within HTML <href> tags may cause SpamProbe to crash. This occurs when parsing the tag with a regular expression.
This issue has been reported to occur on RedHat 8.0. It is not yet known whether SpamProbe is prone to this issue when running on other distributions or operating systems.
Exploit / POC
SpamProbe Remote Denial of Service Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
SpamProbe Remote Denial of Service Vulnerability
Solution:
This issue has been addressed in SpamProbe 0.8b. Users are advised to upgrade as soon as possible.
SpamProbe SpamProbe 0.8 a
Solution:
This issue has been addressed in SpamProbe 0.8b. Users are advised to upgrade as soon as possible.
SpamProbe SpamProbe 0.8 a
-
SpamProbe SpamProbe 0.8b
http://sourceforge.net/project/showfiles.php?group_id=61201