CVE Database
/

CVE-2018-11805

Back to search

CVE-2018-11805

Published: Dec 12, 2019

Modified: Aug 5, 2024

PUBLISHED

Description

In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we recommend that users should only use update channels or 3rd party .cf files from trusted places.

VendorProductVersions

Apache

Apache SpamAssassin

affected
Apache SpamAssassin prior to 3.4.3

References

DSA-4584
vendor-advisory
x_refsource_DEBIAN
USN-4237-1
vendor-advisory
x_refsource_UBUNTU
USN-4237-2
vendor-advisory
x_refsource_UBUNTU
openSUSE-SU-2020:0446
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now