Common vulnerabilities and Exposures (CVE)

Skip to main content

Required CVE Record Information

Description

The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 downloads files and trusts them without using encryption (e.g., https) or digital signature checking which could allow an attacker to replace certain configuration files (e.g., phishing whitelist) via dns/packet spoofing.

Updated:

This container includes required additional information provided by the CVE Program for this vulnerability.