PT-2019-5236 · Apache+5 · Apache Spamassassin+5

Kevin A. Mcgrail

·

Published

2019-12-11

·

Updated

2024-06-15

·

CVE-2018-11805

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache SpamAssassin versions prior to 3.4.3
Description The issue is related to the lack of measures to neutralize special elements used in the operating system command. This can allow an attacker to gain unauthorized access to confidential data, cause a denial of service, and impact data integrity. Exploits can be injected in various scenarios, and users are advised to only use update channels or third-party configuration files from trusted sources.
Recommendations For versions prior to 3.4.3, upgrade to Apache SpamAssassin 3.4.3 to resolve the issue. As a temporary workaround, consider restricting the use of external configuration files until the issue is resolved. Avoid using untrusted update channels or third-party configuration files to minimize the risk of exploitation.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1004
ALT-PU-2020-1005
ALT-PU-2020-1038
ALT-PU-2020-1039
BDU:2020-00654
BDU:2020-01979
CESA-2020_4625
CVE-2018-11805
DLA-2037-1
DLA-2062-1
DSA-4584-1
MGASA-2019-0406
OPENSUSE-SU-2020:0446-1
OPENSUSE-SU-2020_0446-1
OPENSUSE-SU-2024:11395-1
RHSA-2020:4625
RHSA-2020_4625
SUSE-SU-2020:0810-1
SUSE-SU-2020:0811-1
SUSE-SU-2020:0813-1
SUSE-SU-2020_0810-1
SUSE-SU-2020_0811-1
SUSE-SU-2020_0813-1
USN-4237-1
USN-4237-2

Affected Products

Alt Linux
Apache Spamassassin
Centos
Red Hat
Suse
Ubuntu