Smokey's Security Weblog

veritas odium parit

Spamassasin Y2K10 Rule Bug – Update Your Rules Now!

The Apache SpamAssassin Project – 2010-01-01

Versions of the FH_DATE_PAST_20XX rule released with versions of Apache SpamAssassin 3.2.0 thru 3.2.5 will trigger on most mail with a Date header that includes the year 2010 or later. The rule will add a score of up to 3.6 towards the spam classification of all email. You should take corrective action immediately; there are two easy ways to correct the problem:

– If your system is configured to use sa-update run sa-update now. An update is available that will correct the rule. No further action is necessary (other than restarting spamd or any service that uses SpamAssassin directly).

– Add “score FH_DATE_PAST_20XX 0” without the quotes to the end of your local.cf file to disable the rule.

If you require help updating your rules to correct this issue you are encouraged to ask for assistance on the Apache SpamAssassin Users’ list. Users’ mailing list info is here.

On behalf of the Apache SpamAssassin project I apologize for this error and the grief it may have caused you.

Regards,

Daryl C. W. O’Shea

VP, Apache SpamAssassin

January 2, 2010 - Posted by | Advisories, Alerts, Downloads, Recommended External Security Related Links | , , , , , ,

No comments yet.

Leave a comment