CVE-2007-2873

Publication date 11 June 2007

Last updated 17 July 2025


Ubuntu priority

SpamAssassin 3.1.x, 3.2.0, and 3.2.1 before 20070611, when running as root in unusual configurations using vpopmail or virtual users, allows local users to cause a denial of service (corrupt arbitrary files) via a symlink attack on a file that is used by spamd.

Status

Package Ubuntu Release Status
spamassassin 9.10 karmic
Fixed 3.2.2-0ubuntu1
9.04 jaunty
Fixed 3.2.2-0ubuntu1
8.10 intrepid
Fixed 3.2.2-0ubuntu1
8.04 LTS hardy
Fixed 3.2.2-0ubuntu1
7.10 gutsy
Fixed 3.2.2-0ubuntu1
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life