← Vulnerability feed

Vulnerability record · CVE-2006-2447 · published 6 June 2006

CVE-2006-2447: SpamAssassin vpopmail paranoid mode command injection

Apache · Spamassassin

SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, fails to properly handle the virtual pop username when invoking spamd, allowing command injection. A crafted message can cause arbitrary command execution on the mail server. This matters because it turns a mail-processing path into remote code execution on systems using that specific configuration.

5.1 CVSS 2.0 Medium EPSS 76% · top 0.5%
5.1CVSS 2.0 base score
76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
38References
16 Jun 2026Last modified by NVD

Description

SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly handled when invoking spamd with the virtual pop username.

AV:N/AC:H/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityRemote code execution with no authentication required, though it depends on a specific vpopmail and paranoid-mode configuration, and EPSS is very high.

What it is

SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, fails to properly handle the virtual pop username when invoking spamd, allowing command injection. A crafted message can cause arbitrary command execution on the mail server. This matters because it turns a mail-processing path into remote code execution on systems using that specific configuration.

Impact

An attacker can execute arbitrary commands with the privileges of the spamd process, potentially compromising the mail server. This can lead to data theft, further lateral movement, or service disruption.

Attack surface

The flaw is reached remotely by sending a crafted email message to a SpamAssassin instance configured with vpopmail and the paranoid (-P) switch. No authentication is required, and no user interaction is needed beyond message delivery.

Exploitation

The record is not listed in CISA KEV and has no exploit tags in references, but EPSS is very high (0.7581, 99.5th percentile), indicating elevated predicted exploitation likelihood. No public exploit details are provided in the record.

What to do

  • Upgrade SpamAssassin to 3.1.3 or later, applying vendor patches referenced in the advisories.
  • If immediate patching is not possible, disable the paranoid (-P) switch or avoid running spamd with vpopmail in that mode.
  • Restrict network access to spamd so only trusted mail transfer agents can reach it.
  • Run spamd with least privilege and isolate it from sensitive system resources.
  • Monitor vendor advisories for distribution-specific patches (Debian, Red Hat, Gentoo, Mandriva, Trustix).

Detection

  • Inspect spamd process command lines for the -P switch combined with vpopmail configuration.
  • Monitor for unexpected child processes or shell commands spawned by spamd.
  • Review mail logs for anomalous messages that trigger spamd errors or unusual username handling.
  • Audit systems for SpamAssassin versions prior to 3.1.3 using package managers or version checks.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/20430 PatchVendor Advisory
http://secunia.com/advisories/20443 PatchVendor Advisory
http://secunia.com/advisories/20482 Vendor Advisory
http://secunia.com/advisories/20531 Vendor Advisory
http://secunia.com/advisories/20566 Vendor Advisory
http://secunia.com/advisories/20692 Vendor Advisory
http://securitytracker.com/id?1016230
http://securitytracker.com/id?1016235
http://www.debian.org/security/2006/dsa-1090 PatchVendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200606-09.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:103
http://www.nabble.com/ANNOUNCE%3A-Apache-SpamAssassin-3.1.3-available%21-t1736096.html Patch
http://www.redhat.com/support/errata/RHSA-2006-0543.html PatchVendor Advisory
http://www.securityfocus.com/archive/1/436288/100/0/threaded
http://www.securityfocus.com/bid/18290 Patch
http://www.trustix.org/errata/2006/0034/
http://www.vupen.com/english/advisories/2006/2148 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/27008
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9184
http://secunia.com/advisories/20430 PatchVendor Advisory
http://secunia.com/advisories/20443 PatchVendor Advisory
http://secunia.com/advisories/20482 Vendor Advisory
http://secunia.com/advisories/20531 Vendor Advisory
http://secunia.com/advisories/20566 Vendor Advisory
http://secunia.com/advisories/20692 Vendor Advisory
http://securitytracker.com/id?1016230
http://securitytracker.com/id?1016235
http://www.debian.org/security/2006/dsa-1090 PatchVendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200606-09.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:103
http://www.nabble.com/ANNOUNCE%3A-Apache-SpamAssassin-3.1.3-available%21-t1736096.html Patch
http://www.redhat.com/support/errata/RHSA-2006-0543.html PatchVendor Advisory
http://www.securityfocus.com/archive/1/436288/100/0/threaded
http://www.securityfocus.com/bid/18290 Patch
http://www.trustix.org/errata/2006/0034/
http://www.vupen.com/english/advisories/2006/2148 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/27008
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9184

Track CVE-2006-2447 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-1946Apache spamassassin os command injection vulnerabilityIn Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. …EPSS 6.1%9.8CVE-2018-11780Apache spamassassin code injection vulnerabilityA potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.EPSS 11%8.1CVE-2020-1930Apache spamassassin os command injection vulnerabilityA command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious rule configuration (.cf) files can be configur…EPSS 7.1%8.1CVE-2020-1931Apache spamassassin os command injection vulnerabilityA command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious Configuration (.cf) files can be configured to…EPSS 6.5%7.8CVE-2018-11781Apache spamassassin code injection vulnerabilityApache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.EPSS 0.98%7.8CVE-2016-1238Debian linux permissions and access controls vulnerability(1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/…EPSS 0.78%7.5CVE-2019-12420Apache spamassassin uncontrolled resource consumption vulnerabilityIn Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the r…EPSS 7.2%6.7CVE-2018-11805Apache spamassassin os command injection vulnerabilityIn Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits ca…EPSS 0.87%

Source: NIST National Vulnerability Database (record CVE-2006-2447), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.