CVE-2010-3292
12.11.2019, 21:15
The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 downloads files and trusts them without using encryption (e.g., https) or digital signature checking which could allow an attacker to replace certain configuration files (e.g., phishing whitelist) via dns/packet spoofing.Enginsight
Vendor | Product | Version |
---|---|---|
mailscanner | mailscanner | 4.79.11-2 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References