Required CVE Record Information
Description
The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 downloads files and trusts them without using encryption (e.g., https) or digital signature checking which could allow an attacker to replace certain configuration files (e.g., phishing whitelist) via dns/packet spoofing.
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- https://security-tracker.debian.org/tracker/CVE-2010-3292 x_transferred
- https://access.redhat.com/security/cve/cve-2010-3292 x_transferred
- openwall.com: [oss-security] 20100913 Re: CVE request: mailscanner, multiple vulnerabilities mailing-listx_transferred
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=596396 x_transferred