Executive Summary

Informations
Name CVE-2007-2873 First vendor Publication 2007-06-11
Vendor Cve Last vendor Modification 2017-10-11

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:M/Au:N/C:N/I:N/A:P)
Cvss Base Score 1.9 Attack Range Local
Cvss Impact Score 2.9 Attack Complexity Medium
Cvss Expoit Score 3.4 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

SpamAssassin 3.1.x, 3.2.0, and 3.2.1 before 20070611, when running as root in unusual configurations using vpopmail or virtual users, allows local users to cause a denial of service (corrupt arbitrary files) via a symlink attack on a file that is used by spamd.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2873

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:10354
 
Oval ID: oval:org.mitre.oval:def:10354
Title: SpamAssassin 3.1.x, 3.2.0, and 3.2.1 before 20070611, when running as root in unusual configurations using vpopmail or virtual users, allows local users to cause a denial of service (corrupt arbitrary files) via a symlink attack on a file that is used by spamd.
Description: SpamAssassin 3.1.x, 3.2.0, and 3.2.1 before 20070611, when running as root in unusual configurations using vpopmail or virtual users, allows local users to cause a denial of service (corrupt arbitrary files) via a symlink attack on a file that is used by spamd.
Family: unix Class: vulnerability
Reference(s): CVE-2007-2873
Version: 5
Platform(s): Red Hat Enterprise Linux 4
CentOS Linux 4
Oracle Linux 4
Red Hat Enterprise Linux 5
CentOS Linux 5
Oracle Linux 5
Product(s):
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:22689
 
Oval ID: oval:org.mitre.oval:def:22689
Title: ELSA-2007:0492: spamassassin security update (Moderate)
Description: SpamAssassin 3.1.x, 3.2.0, and 3.2.1 before 20070611, when running as root in unusual configurations using vpopmail or virtual users, allows local users to cause a denial of service (corrupt arbitrary files) via a symlink attack on a file that is used by spamd.
Family: unix Class: patch
Reference(s): ELSA-2007:0492-02
CVE-2007-2873
Version: 6
Platform(s): Oracle Linux 5
Product(s): spamassassin
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 12

OpenVAS Exploits

Date Description
2009-04-09 Name : Mandriva Update for spamassassin MDKSA-2007:125 (spamassassin)
File : nvt/gb_mandriva_MDKSA_2007_125.nasl
2009-02-27 Name : Fedora Update for spamassassin FEDORA-2007-0390
File : nvt/gb_fedora_2007_0390_spamassassin_fc7.nasl
2009-02-27 Name : Fedora Update for spamassassin FEDORA-2007-582
File : nvt/gb_fedora_2007_582_spamassassin_fc6.nasl
2009-02-27 Name : Fedora Update for spamassassin FEDORA-2007-584
File : nvt/gb_fedora_2007_584_spamassassin_fc5.nasl
2008-09-04 Name : FreeBSD Ports: p5-Mail-SpamAssassin
File : nvt/freebsd_p5-Mail-SpamAssassin2.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
37234 SpamAssassin spamd Symlink Local DoS

Nessus® Vulnerability Scanner

Date Description
2013-07-12 Name : The remote Oracle Linux host is missing a security update.
File : oraclelinux_ELSA-2007-0492.nasl - Type : ACT_GATHER_INFO
2012-08-01 Name : The remote Scientific Linux host is missing a security update.
File : sl_20070613_spamassassin_on_SL5_x.nasl - Type : ACT_GATHER_INFO
2007-11-06 Name : The remote Fedora host is missing a security update.
File : fedora_2007-0390.nasl - Type : ACT_GATHER_INFO
2007-06-18 Name : The remote CentOS host is missing a security update.
File : centos_RHSA-2007-0492.nasl - Type : ACT_GATHER_INFO
2007-06-18 Name : The remote FreeBSD host is missing a security-related update.
File : freebsd_pkg_8092b8201d6f11dca0b2001921ab2fa4.nasl - Type : ACT_GATHER_INFO
2007-06-18 Name : The remote Mandrake Linux host is missing one or more security updates.
File : mandrake_MDKSA-2007-125.nasl - Type : ACT_GATHER_INFO
2007-06-14 Name : The remote Fedora Core host is missing a security update.
File : fedora_2007-582.nasl - Type : ACT_GATHER_INFO
2007-06-14 Name : The remote Fedora Core host is missing a security update.
File : fedora_2007-584.nasl - Type : ACT_GATHER_INFO
2007-06-14 Name : The remote Red Hat host is missing a security update.
File : redhat-RHSA-2007-0492.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

Source Url
BID http://www.securityfocus.com/bid/24481
CONFIRM http://spamassassin.apache.org/advisories/cve-2007-2873.txt
https://issues.rpath.com/browse/RPL-1450
MANDRIVA http://www.mandriva.com/security/advisories?name=MDKSA-2007:125
OSVDB http://osvdb.org/37234
OVAL https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
REDHAT http://www.redhat.com/support/errata/RHSA-2007-0492.html
SECTRACK http://www.securitytracker.com/id?1018242
VUPEN http://www.vupen.com/english/advisories/2007/2172
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/34864

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
Date Informations
2021-05-04 12:05:50
  • Multiple Updates
2021-04-22 01:06:23
  • Multiple Updates
2020-05-23 00:19:50
  • Multiple Updates
2017-10-11 09:23:58
  • Multiple Updates
2017-07-29 12:02:16
  • Multiple Updates
2016-06-28 16:32:41
  • Multiple Updates
2016-04-26 16:10:50
  • Multiple Updates
2014-02-17 10:40:19
  • Multiple Updates
2013-05-11 10:27:02
  • Multiple Updates