Medium severity5.5NVD Advisory· Published Nov 12, 2019· Updated Jun 16, 2026
CVE-2010-3292
CVE-2010-3292
Description
The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 downloads files and trusts them without using encryption (e.g., https) or digital signature checking which could allow an attacker to replace certain configuration files (e.g., phishing whitelist) via dns/packet spoofing.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:mailscanner:mailscanner:4.79.11-2:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:mailscanner:mailscanner:4.79.11-2:*:*:*:*:*:*:*
- (no CPE)range: =4.79.11-2
- (no CPE)range: 4.79.11-2
Patches
Vulnerability mechanics
References
4- bugs.debian.org/cgi-bin/bugreport.cginvdMailing ListThird Party Advisory
- security-tracker.debian.org/tracker/CVE-2010-3292nvdThird Party Advisory
- www.openwall.com/lists/oss-security/2010/09/13/9nvdMailing ListThird Party Advisory
- access.redhat.com/security/cve/cve-2010-3292nvdBroken Link
News mentions
0No linked articles in our index yet.