CVE-2017-15705

A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. The vulnerability arises with certain unclosed tags in emails that cause markup to be handled incorrectly leading to scan timeouts. In Apache SpamAssassin, using HTML::Parser, we setup an object and hook into the begin and end tag event handlers In both cases, the "open" event is immediately followed by a "close" event - even if the tag *does not* close in the HTML being parsed. Because of this, we are missing the "text" event to deal with the object normally. This can cause carefully crafted emails that might take more scan time than expected leading to a Denial of Service. The issue is possibly a bug or design decision in HTML::Parser that specifically impacts the way Apache SpamAssassin uses the module with poorly formed html. The exploit has been seen in the wild but not believed to have been purposefully part of a Denial of Service attempt. We are concerned that there may be attempts to abuse the vulnerability in the future.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
Affected Products (NVD)
VendorProductVersion
apachespamassassin
𝑥
< 3.4.2
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
16.04
canonicalubuntu_linux
18.04
debiandebian_linux
8.0
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_eus
7.5
redhatenterprise_linux_server
7.0
redhatenterprise_linux_workstation
7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
spamassassin
bookworm
4.0.0-6
fixed
bullseye
3.4.6-1
fixed
sid
4.0.1-2
fixed
trixie
4.0.1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
spamassassin
bionic
Fixed 3.4.2-0ubuntu0.18.04.1
released
cosmic
not-affected
trusty
Fixed 3.4.2-0ubuntu0.14.04.1
released
xenial
Fixed 3.4.2-0ubuntu0.16.04.1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
perl-Mail-SpamAssassin
suse enterprise desktop 15
3.4.2-7.4.1
fixed
suse enterprise desktop 15 SP1
3.4.2-10.19
fixed
suse enterprise desktop 15 SP2
3.4.2-12.5.1
fixed
suse enterprise desktop 15 SP3
3.4.5-12.10.1
fixed
suse enterprise desktop 15 SP4
3.4.5-12.13.1
fixed
suse enterprise desktop 15 SP5
3.4.5-12.13.1
fixed
suse enterprise desktop 15 SP6
3.4.5-150600.23.4
fixed
suse enterprise desktop 15 SP7
3.4.5-150600.23.4
fixed
suse enterprise sap 12 SP4
3.4.2-44.3.1
fixed
suse enterprise sap 12 SP5
3.4.2-44.3.1
fixed
suse enterprise sap 15
3.4.2-7.4.1
fixed
suse enterprise sap 15 SP1
3.4.2-10.19
fixed
suse enterprise sap 15 SP2
3.4.2-12.5.1
fixed
suse enterprise sap 15 SP3
3.4.5-12.10.1
fixed
suse enterprise sap 15 SP4
3.4.5-12.13.1
fixed
suse enterprise sap 15 SP5
3.4.5-12.13.1
fixed
suse enterprise sap 15 SP6
3.4.5-150600.23.4
fixed
suse enterprise sap 15 SP7
3.4.5-150600.23.4
fixed
suse enterprise server 12 SP3
3.4.2-44.3.1
fixed
suse enterprise server 12 SP4
3.4.2-44.3.1
fixed
suse enterprise server 12 SP5
3.4.2-44.3.1
fixed
suse enterprise server 15
3.4.2-7.4.1
fixed
suse enterprise server 15 SP1
3.4.2-10.19
fixed
suse enterprise server 15 SP2
3.4.2-12.5.1
fixed
suse enterprise server 15 SP3
3.4.5-12.10.1
fixed
suse enterprise server 15 SP4
3.4.5-12.13.1
fixed
suse enterprise server 15 SP5
3.4.5-12.13.1
fixed
suse enterprise server 15 SP6
3.4.5-150600.23.4
fixed
suse enterprise server 15 SP7
3.4.5-150600.23.4
fixed
spamassassin
suse enterprise desktop 15
3.4.2-7.4.1
fixed
suse enterprise desktop 15 SP1
3.4.2-10.19
fixed
suse enterprise desktop 15 SP2
3.4.2-12.5.1
fixed
suse enterprise desktop 15 SP3
3.4.5-12.10.1
fixed
suse enterprise desktop 15 SP4
3.4.5-12.13.1
fixed
suse enterprise desktop 15 SP5
3.4.5-12.13.1
fixed
suse enterprise desktop 15 SP6
3.4.5-150600.23.4
fixed
suse enterprise desktop 15 SP7
3.4.5-150600.23.4
fixed
suse enterprise sap 12 SP4
3.4.2-44.3.1
fixed
suse enterprise sap 12 SP5
3.4.2-44.3.1
fixed
suse enterprise sap 15
3.4.2-7.4.1
fixed
suse enterprise sap 15 SP1
3.4.2-10.19
fixed
suse enterprise sap 15 SP2
3.4.2-12.5.1
fixed
suse enterprise sap 15 SP3
3.4.5-12.10.1
fixed
suse enterprise sap 15 SP4
3.4.5-12.13.1
fixed
suse enterprise sap 15 SP5
3.4.5-12.13.1
fixed
suse enterprise sap 15 SP6
3.4.5-150600.23.4
fixed
suse enterprise sap 15 SP7
3.4.5-150600.23.4
fixed
suse enterprise server 12 SP3
3.4.2-44.3.1
fixed
suse enterprise server 12 SP4
3.4.2-44.3.1
fixed
suse enterprise server 12 SP5
3.4.2-44.3.1
fixed
suse enterprise server 15
3.4.2-7.4.1
fixed
suse enterprise server 15 SP1
3.4.2-10.19
fixed
suse enterprise server 15 SP2
3.4.2-12.5.1
fixed
suse enterprise server 15 SP3
3.4.5-12.10.1
fixed
suse enterprise server 15 SP4
3.4.5-12.13.1
fixed
suse enterprise server 15 SP5
3.4.5-12.13.1
fixed
suse enterprise server 15 SP6
3.4.5-150600.23.4
fixed
suse enterprise server 15 SP7
3.4.5-150600.23.4
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
spamassassin
RHEL 7
0:3.4.0-4.el7_5
fixed