CVE-2017-15705 is a denial-of-service vulnerability affecting Apache SpamAssassin before version 3.4.2, as well as products from Canonical, Debian, and Red Hat. Maliciously crafted emails with unclosed HTML tags can cause scan timeouts due to incorrect markup handling. This vulnerability has a CVSS score of 5.3 (Medium), indicating a low attack complexity and no user interaction required, leading to a potential loss of availability. While the exploit has been observed in the wild, it is not believed to have been part of a deliberate denial-of-service attempt, and there is no known public exploit code or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.4.2CPE matchmatch criteria | cpe:2.3:a:apache:spamassassin:*:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.