Alerts This Week
Warning Icon 1 933
Alerts This Week
Warning Icon 1 933

Mageia 7 MGASA-2020-0079 Moderate: Spamassassin Command Execution Threat

mageia
Calendar Grey February 9, 2020
Dist Mageia Esm H88
Mageia's MGASA-2020-0080 update enhances libxml2 to fix critical security flaws in XML parsing.
The updated packages fix security vulnerabilities: Nefarious rule configuration (.cf) files can be configured to run system commands with sa-compile

Summary

The updated packages fix security vulnerabilities:
Nefarious rule configuration (.cf) files can be configured to run system commands with sa-compile. (CVE-2020-1930)
Nefarious rule configuration (.cf) files can be configured to run system commands with warnings. (CVE-2020-1931)

References

- https://bugs.mageia.org/show_bug.cgi?id=26150

- https://spamassassin.apache.org/news.html

- https://svn.apache.org/repos/asf/spamassassin/branches/3.4/build/announcements/3.4.4.txt

- https://www.openwall.com/lists/oss-security/2020/01/30/3

- https://www.openwall.com/lists/oss-security/2020/01/30/2

- https://www.cve.org/CVERecord?id=CVE-2020-1930

- https://www.cve.org/CVERecord?id=CVE-2020-1931

Resolution

SRPMS

- 7/core/spamassassin-3.4.4-1.mga7

- 7/core/spamassassin-rules-3.4.4-1.mga7

Publication date: 09 Feb 2020
URL: https://advisories.mageia.org/MGASA-2020-0079.html
Type: security
CVE: CVE-2020-1930, CVE-2020-1931

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here