Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Debian LTS: DLA-2037-1 Critical: spamassassin Arbitrary Command Execution

debian lts
Calendar Grey December 16, 2019
Dist Debian Esm H88
Crucial enhancements for SpamAssassin in Debian LTS address multiple security flaws and improve overall performance.
Two vulnerabilities were discovered in spamassassin, a Perl-based spam filter using text analysis

Summary

Malicious rule or configuration files, possibly downloaded from an
updates server, could execute arbitrary commands under multiple
scenarios.

CVE-2019-12420

Specially crafted mulitpart messages can cause spamassassin to use
excessive resources, resulting in a denial of service.

For Debian 8 "Jessie", these problems have been fixed in version
3.4.2-0+deb8u2.

We recommend that you upgrade your spamassassin packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: spamassassin
Version: 3.4.2-0+deb8u2
CVE ID: CVE-2018-11805 CVE-2019-12420
Debian Bug: 946652 946653

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here