SpamAssassin 3.1.8 was released. SpamAssassin is the leading spamfilter written in Perl. This is a maintenance and security release of the 3.1.x branch. It is highly recommended that people upgrade to this version. This latest update covers, amongst other things, the following:

  • bug 5318: fix for CVE-2007-0451: possible DoS due to incredibly long URIs found in the message content.
  • bug 5240: disable perl module usage in update channels unless –allowplugins is specified
  • bug 5288: files with names starting/ending in whitespace weren’t usable
  • bug 5056: remove Text::Wrap related code due to upstream issues
  • bug 5145: update spamassassin and sa-learn to better deal with STDIN
  • bug 5140 and 5179: improvements and bug fixes related to DomainKeys and DKIM support
  • several updates for Received header parsing
  • several documentation updates and random taint-variable related issues

A more detailed change log can be read here.