PT-2018-1925 · Apache+3 · Apache Spamassassin+3

Publicado

2018-09-16

·

Atualizado

2024-06-15

·

CVE-2018-11780

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache SpamAssassin versions prior to 3.4.2
Description A potential Remote Code Execution issue exists with the PDFInfo plugin in Apache SpamAssassin. The vulnerability is related to errors in code generation management. Exploitation of this issue may allow a remote attacker to execute arbitrary code.
Recommendations For versions prior to 3.4.2, update to version 3.4.2 or later to resolve the issue. As a temporary workaround, consider disabling the PDFInfo plugin until a patch is available.

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2985
ALT-PU-2018-2986
BDU:2018-01532
CVE-2018-11780
DLA-1578-1
MGASA-2018-0425
OPENSUSE-SU-2019:1831-1
OPENSUSE-SU-2019_1831-1
OPENSUSE-SU-2024:11395-1
SUSE-SU-2019:1961-1
SUSE-SU-2019:2011-1
USN-3811-1
USN-3811-3

Produtos afetados

Alt Linux
Apache Spamassassin
Suse
Ubuntu