Apache · Apache Spamassassin · CVE-2020-1930
**Name of the Vulnerable Software and Affected Versions**
Apache SpamAssassin versions prior to 3.4.3
**Description**
The issue is related to a command execution problem in the spam filter, potentially allowing a remote attacker to access confidential data, compromise its integrity, and cause a denial of service. This can occur due to malicious rule configuration files that could be downloaded from an update server. The exploitation may involve running system commands with elevated privileges, although remote exploitation is considered difficult. It is recommended to only use trusted update channels and third-party configuration files to minimize the risk.
**Recommendations**
For versions prior to 3.4.3, upgrade to Apache SpamAssassin 3.4.4 to resolve the issue.
As a temporary workaround, consider not using third-party rulesets and avoid running spamd with elevated privileges until the issue is resolved.
Additionally, refrain from using sa-compile until a patch is applied.