Back to Database
Status published
Medium
CVE-2005-3351
SpamAssassin 3.0.4 allows attackers to bypass spam detection via an...
Vulnerability Description
SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2005-3351
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23048
- http://secunia.com/advisories/17518/
- http://issues.apache.org/SpamAssassin/show_bug.cgi?id=4570
- http://secunia.com/advisories/17666/
- http://secunia.com/advisories/17626/
- http://secunia.com/advisories/19158
- http://secunia.com/advisories/17386/
- http://www.securityfocus.com/bid/15373
- http://lwn.net/Alerts/159300/
- http://www.gossamer-threads.com/lists/spamassassin/devel/62649
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11125
- http://www.redhat.com/support/errata/RHSA-2006-0129.html
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:221
- http://www.vupen.com/english/advisories/2005/2364
- http://osvdb.org/11581
- http://www.novell.com/linux/security/advisories/2005_27_sr.html
- http://secunia.com/advisories/17877
More from apache
View All →CVE-2025-58712
Amq: privilege escalation via excessive /etc/passwd permissions
Medium
6.4
CVE-2021-25958
Generation of Error Message Containing Sensitive Information in Apache OFBiz
Medium
6.5
CVE-2021-24117
In Apache Teaclave Rust SGX SDK 1.1.3, a side-channel vulnerability...
Medium
4.9
CVE-2020-5499
Baidu Rust SGX SDK through 1.0.8 has an enclave ID...
Critical
9.8
CVE-2018-14889
CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3...
High
7.8
Affected Vendor
apache
View all reports →Affected Software
spamassassin
Vulnerable Versions:
3.0.4
Timeline
Official Publish:
November 20th, 2005
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.