Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update for spamassassin is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: spamassassin security update Advisory ID: RHSA-2021:4315-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:4315 Issue date: 2021-11-09 CVE Names: CVE-2020-1946 ==================================================================== 1. Summary: An update for spamassassin is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: The SpamAssassin tool provides a way to reduce unsolicited commercial email (spam) from incoming email. Security Fix(es): * spamassassin: Malicious rule configuration files can be configured to run system commands (CVE-2020-1946) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.5 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1943276 - CVE-2020-1946 spamassassin: Malicious rule configuration files can be configured to run system commands 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: spamassassin-3.4.4-4.el8.src.rpm aarch64: spamassassin-3.4.4-4.el8.aarch64.rpm spamassassin-debuginfo-3.4.4-4.el8.aarch64.rpm spamassassin-debugsource-3.4.4-4.el8.aarch64.rpm ppc64le: spamassassin-3.4.4-4.el8.ppc64le.rpm spamassassin-debuginfo-3.4.4-4.el8.ppc64le.rpm spamassassin-debugsource-3.4.4-4.el8.ppc64le.rpm s390x: spamassassin-3.4.4-4.el8.s390x.rpm spamassassin-debuginfo-3.4.4-4.el8.s390x.rpm spamassassin-debugsource-3.4.4-4.el8.s390x.rpm x86_64: spamassassin-3.4.4-4.el8.x86_64.rpm spamassassin-debuginfo-3.4.4-4.el8.x86_64.rpm spamassassin-debugsource-3.4.4-4.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2020-1946 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/8.5_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYYreB9zjgjWX9erEAQirBw//T0QpMvxIMQEeW+G8tLob/7UUKJ4YmdNT tIMLLPobvJZi2nfSAU/xU6nHOwgbsswXA7Be049NB1E6VSJktp6MQjiAemRipas0 Tde4xkJSRkTEqb5wLzSvLnesUuuw1/VLxtkD5aIVRoqJ2IhGZKZB0ffsFD+V9AFc UPw0y6pTj5tXs2HvLZ7by63ufcdEBrJls4etEAHWfD7OKc1ZSZ/OIr4o5Qhiieog QVyqdn8B8sULEAbASEaUmQtUfkFPD4DKP84pylmndX9UUigIJcRXYZOmF2q8C5ok Q7mx9iEA8nZy+T0C5MPWrCmpR5qiIocFjSi+IE+HgymX50J+krdZcZ8eeYblI65V TOjeodJBQeieEAagbY+8QpWM92vK8uJ+YZ/dlB1t19nPNnKidDTPjVz0IPNX6MDA OyAfdTwLcQxDgJBOFP9F+vgvKjjciPbnbVO4D4QpYtR4HBQp7tKgOIZHrGIG3eUR gaR+7XE7CffgdDGlzrEKSsIfkn+9AtxgfREv7Z1oYfRfv1dbr42LYZyqJli1Bwlw zfA3GcEoWDPPwsxTF2MZg/wwYuYBIaPLrRqNEtZvC5g1YPRT5RX6DMMvSoT5NZMt IAfpqoTrVa2YJjBfYm/nRhYFcxioqXQ9C/9jisOTidGZeoNTgY5XisWAbJj+fLRw wCZUEDzBG5g=QSzU -----END PGP SIGNATURE----- -- RHSA-announce mailing list
A vulnerability in SpamAssassin might allow remote attackers to execute arbitrary commands.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202105-26 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: SpamAssassin: Arbitrary command execution Date: May 26, 2021 Bugs: #778002 ID: 202105-26 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability in SpamAssassin might allow remote attackers to execute arbitrary commands. Background ========= SpamAssassin is an extensible email filter used to identify junk email. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 mail-filter/spamassassin < 3.4.5 > = 3.4.5 Description ========== It was discovered that SpamAssassin incorrectly handled certain CF files. Impact ===== A remote attacker could entice a user or automated system to process a specially crafted CF file using SpamAssassin, possibly resulting in execution of arbitrary commands with the privileges of the process or a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All SpamAssassin users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =mail-filter/spamassassin-3.4.5" References ========= [ 1 ] CVE-2020-1946 https://nvd.nist.gov/vuln/detail/CVE-2020-1946 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202105-26 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
An update that fixes two vulnerabilities is now available. . openSUSE Security Update: Security update for spamassassin ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0551-1 Rating: important References: #1159133 #1184221 Cross-References: CVE-2019-12420 CVE-2020-1946 CVSS scores: CVE-2019-12420 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2019-12420 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2020-1946 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for spamassassin fixes the following issues: - CVE-2019-12420: memory leak via crafted messages (bsc#1159133) - CVE-2020-1946: security update (bsc#1184221) This update was imported from the SUSE:SLE-15-SP1:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-551=1 Package List: - openSUSE Leap 15.2 (x86_64): perl-Mail-SpamAssassin-3.4.5-lp152.10.3.1 perl-Mail-SpamAssassin-Plugin-iXhash2-2.05-lp152.10.3.1 spamassassin-3.4.5-lp152.10.3.1 spamassassin-debuginfo-3.4.5-lp152.10.3.1 spamassassin-debugsource-3.4.5-lp152.10.3.1 References: https://www.suse.com/security/cve/CVE-2019-12420.html https://www.suse.com/security/cve/CVE-2020-1946.html https://bugzilla.suse.com/1159133 https://bugzilla.suse.com/1184221 . Important openSUSE patch addresses memory leaks and security vulnerabilities in clamav, boosting overall systemsecurity.. openSUSE Security Update, spamassassin fix, memory leak, critical patch, system protection. . Severity: Important. LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for spamassassin ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:1163-1 Rating: important References: #1159133 #1184221 Cross-References: CVE-2019-12420 CVE-2020-1946 CVSS scores: CVE-2019-12420 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2019-12420 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2020-1946 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Manager Server 4.0 SUSE Manager Retail Branch Server 4.0 SUSE Manager Proxy 4.0 SUSE Linux Enterprise Server for SAP 15-SP1 SUSE Linux Enterprise Server 15-SP1-LTSS SUSE Linux Enterprise Server 15-SP1-BCL SUSE Linux Enterprise Module for Development Tools 15-SP3 SUSE Linux Enterprise Module for Development Tools 15-SP2 SUSE Linux Enterprise Module for Basesystem 15-SP3 SUSE Linux Enterprise Module for Basesystem 15-SP2 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS SUSE Enterprise Storage 6 SUSE CaaS Platform 4.0 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for spamassassin fixes the following issues: - CVE-2019-12420: memory leak via crafted messages (bsc#1159133) - CVE-2020-1946: security update (bsc#1184221) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Manager Server 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.0-2021-1163=1 - SUSE Manager Retail Branch Server 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.0-2021-1163=1 - SUSE Manager Proxy 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.0-2021-1163=1 - SUSE Linux Enterprise Server for SAP 15-SP1: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2021-1163=1 - SUSE Linux Enterprise Server 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2021-1163=1 - SUSE Linux Enterprise Server 15-SP1-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-BCL-2021-1163=1 - SUSE Linux Enterprise Module for Development Tools 15-SP3: zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP3-2021-1163=1 - SUSE Linux Enterprise Module for Development Tools 15-SP2: zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP2-2021-1163=1 - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP3-2021-1163=1 - SUSE Linux Enterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2021-1163=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2021-1163=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-ESPOS-2021-1163=1 - SUSE Enterprise Storage 6: zypper in -t patch SUSE-Storage-6-2021-1163=1 - SUSE CaaS Platform 4.0: To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE Manager Server 4.0 (ppc64le s390x x86_64): perl-Mail-SpamAssassin-3.4.5-12.10.1 perl-Mail-SpamAssassin-Plugin-iXhash2-2.05-12.10.1 spamassassin-3.4.5-12.10.1 spamassassin-debuginfo-3.4.5-12.10.1 spamassassin-debugsource-3.4.5-12.10.1 - SUSE Manager Retail Branch Server 4.0 (x86_64): perl-Mail-SpamAssassin-3.4.5-12.10.1 perl-Mail-SpamAssassin-Plugin-iXhash2-2.05-12.10.1 spamassassin-3.4.5-12.10.1 spamassassin-debuginfo-3.4.5-12.10.1 spamassassin-debugsource-3.4.5-12.10.1 - SUSE Manager Proxy 4.0 (x86_64): perl-Mail-SpamAssassin-3.4.5-12.10.1 perl-Mail-SpamAssassin-Plugin-iXhash2-2.05-12.10.1 spamassassin-3.4.5-12.10.1 spamassassin-debuginfo-3.4.5-12.10.1 spamassassin-debugsource-3.4.5-12.10.1 - SUSE Linux Enterprise Server for SAP 15-SP1 (ppc64le x86_64): perl-Mail-SpamAssassin-3.4.5-12.10.1 perl-Mail-SpamAssassin-Plugin-iXhash2-2.05-12.10.1 spamassassin-3.4.5-12.10.1 spamassassin-debuginfo-3.4.5-12.10.1 spamassassin-debugsource-3.4.5-12.10.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (aarch64 ppc64le s390x x86_64): perl-Mail-SpamAssassin-3.4.5-12.10.1 perl-Mail-SpamAssassin-Plugin-iXhash2-2.05-12.10.1 spamassassin-3.4.5-12.10.1 spamassassin-debuginfo-3.4.5-12.10.1 spamassassin-debugsource-3.4.5-12.10.1 - SUSE Linux Enterprise Server 15-SP1-BCL (x86_64): perl-Mail-SpamAssassin-3.4.5-12.10.1 perl-Mail-SpamAssassin-Plugin-iXhash2-2.05-12.10.1 spamassassin-3.4.5-12.10.1 spamassassin-debuginfo-3.4.5-12.10.1 spamassassin-debugsource-3.4.5-12.10.1 - SUSE Linux Enterprise Module for Development Tools 15-SP3 (aarch64 ppc64le s390x x86_64): perl-Mail-SpamAssassin-Plugin-iXhash2-2.05-12.10.1 - SUSE Linux Enterprise Module for Development Tools 15-SP2 (aarch64 ppc64le s390x x86_64): perl-Mail-SpamAssassin-Plugin-iXhash2-2.05-12.10.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (aarch64 ppc64le s390x x86_64): perl-Mail-SpamAssassin-3.4.5-12.10.1 spamassassin-3.4.5-12.10.1 spamassassin-debuginfo-3.4.5-12.10.1 spamassassin-debugsource-3.4.5-12.10.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (aarch64 ppc64le s390x x86_64): perl-Mail-SpamAssassin-3.4.5-12.10.1 spamassassin-3.4.5-12.10.1 spamassassin-debuginfo-3.4.5-12.10.1 spamassassin-debugsource-3.4.5-12.10.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (aarch64 x86_64): perl-Mail-SpamAssassin-3.4.5-12.10.1 perl-Mail-SpamAssassin-Plugin-iXhash2-2.05-12.10.1 spamassassin-3.4.5-12.10.1 spamassassin-debuginfo-3.4.5-12.10.1 spamassassin-debugsource-3.4.5-12.10.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (aarch64 x86_64): perl-Mail-SpamAssassin-3.4.5-12.10.1 perl-Mail-SpamAssassin-Plugin-iXhash2-2.05-12.10.1 spamassassin-3.4.5-12.10.1 spamassassin-debuginfo-3.4.5-12.10.1 spamassassin-debugsource-3.4.5-12.10.1 - SUSE Enterprise Storage 6 (aarch64 x86_64): perl-Mail-SpamAssassin-3.4.5-12.10.1 perl-Mail-SpamAssassin-Plugin-iXhash2-2.05-12.10.1 spamassassin-3.4.5-12.10.1 spamassassin-debuginfo-3.4.5-12.10.1 spamassassin-debugsource-3.4.5-12.10.1 - SUSE CaaS Platform 4.0 (x86_64): perl-Mail-SpamAssassin-3.4.5-12.10.1 perl-Mail-SpamAssassin-Plugin-iXhash2-2.05-12.10.1 spamassassin-3.4.5-12.10.1 spamassassin-debuginfo-3.4.5-12.10.1 spamassassin-debugsource-3.4.5-12.10.1 References: https://www.suse.com/security/cve/CVE-2019-12420.html https://www.suse.com/security/cve/CVE-2020-1946.html https://bugzilla.suse.com/1159133 https://bugzilla.suse.com/1184221 . A crucial SUSE Security Patch addresses multiple flaws in spamassassin. Discover the steps to implement the update.. SUSE Security Update, Spamassassin Patch, System Security, Patch Management, Vulnerability Fixes. . Severity: Important. LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for spamassassin ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:1153-1 Rating: important References: #1159133 #1184221 Cross-References: CVE-2019-12420 CVE-2020-1946 CVSS scores: CVE-2019-12420 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2019-12420 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2020-1946 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise Server for SAP 15 SUSE Linux Enterprise Server 15-LTSS SUSE Linux Enterprise High Performance Computing 15-LTSS SUSE Linux Enterprise High Performance Computing 15-ESPOS ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for spamassassin fixes the following issues: - CVE-2019-12420: memory leak via crafted messages (bsc#1159133) - CVE-2020-1946: security update (bsc#1184221) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 15: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-2021-1153=1 - SUSE Linux Enterprise Server 15-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-2021-1153=1 - SUSE Linux Enterprise High Performance Computing 15-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-2021-1153=1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-2021-1153=1 Package List: - SUSE Linux Enterprise Server for SAP 15 (ppc64lex86_64): perl-Mail-SpamAssassin-3.4.5-7.14.1 perl-Mail-SpamAssassin-Plugin-iXhash2-2.05-7.14.1 spamassassin-3.4.5-7.14.1 spamassassin-debuginfo-3.4.5-7.14.1 spamassassin-debugsource-3.4.5-7.14.1 - SUSE Linux Enterprise Server 15-LTSS (aarch64 s390x): perl-Mail-SpamAssassin-3.4.5-7.14.1 perl-Mail-SpamAssassin-Plugin-iXhash2-2.05-7.14.1 spamassassin-3.4.5-7.14.1 spamassassin-debuginfo-3.4.5-7.14.1 spamassassin-debugsource-3.4.5-7.14.1 - SUSE Linux Enterprise High Performance Computing 15-LTSS (aarch64 x86_64): perl-Mail-SpamAssassin-3.4.5-7.14.1 perl-Mail-SpamAssassin-Plugin-iXhash2-2.05-7.14.1 spamassassin-3.4.5-7.14.1 spamassassin-debuginfo-3.4.5-7.14.1 spamassassin-debugsource-3.4.5-7.14.1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS (aarch64 x86_64): perl-Mail-SpamAssassin-3.4.5-7.14.1 perl-Mail-SpamAssassin-Plugin-iXhash2-2.05-7.14.1 spamassassin-3.4.5-7.14.1 spamassassin-debuginfo-3.4.5-7.14.1 spamassassin-debugsource-3.4.5-7.14.1 References: https://www.suse.com/security/cve/CVE-2019-12420.html https://www.suse.com/security/cve/CVE-2020-1946.html https://bugzilla.suse.com/1159133 https://bugzilla.suse.com/1184221 . Essential SUSE patch for clamav fixes significant vulnerabilities and performance hiccups to strengthen system integrity.. SUSE Linux Security, SpamAssassin Update, Memory Leak Fix, System Safety, Threat Mitigation. . Severity: Important. LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for spamassassin ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:1152-1 Rating: important References: #1159133 #1184221 Cross-References: CVE-2019-12420 CVE-2020-1946 CVSS scores: CVE-2019-12420 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2019-12420 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2020-1946 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE OpenStack Cloud Crowbar 9 SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 9 SUSE OpenStack Cloud 8 SUSE Linux Enterprise Server for SAP 12-SP4 SUSE Linux Enterprise Server for SAP 12-SP3 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server 12-SP4-LTSS SUSE Linux Enterprise Server 12-SP3-LTSS SUSE Linux Enterprise Server 12-SP3-BCL SUSE Linux Enterprise Server 12-SP2-LTSS-SAP SUSE Linux Enterprise Server 12-SP2-LTSS-ERICSSON SUSE Linux Enterprise Server 12-SP2-BCL HPE Helion Openstack 8 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for spamassassin fixes the following issues: - spamassassin was updated to version 3.4.5 - CVE-2019-12420: memory leak via crafted messages (bsc#1159133) - CVE-2020-1946: security update (bsc#1184221) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listedfor your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2021-1152=1 - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2021-1152=1 - SUSE OpenStack Cloud 9: zypper in -t patch SUSE-OpenStack-Cloud-9-2021-1152=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2021-1152=1 - SUSE Linux Enterprise Server for SAP 12-SP4: zypper in -t patch SUSE-SLE-SAP-12-SP4-2021-1152=1 - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2021-1152=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2021-1152=1 - SUSE Linux Enterprise Server 12-SP4-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP4-LTSS-2021-1152=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2021-1152=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2021-1152=1 - SUSE Linux Enterprise Server 12-SP2-LTSS-SAP: zypper in -t patch SUSE-SLE-SERVER-12-SP2-LTSS-SAP-2021-1152=1 - SUSE Linux Enterprise Server 12-SP2-LTSS-ERICSSON: zypper in -t patch SUSE-SLE-SERVER-12-SP2-LTSS-ERICSSON-2021-1152=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2021-1152=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2021-1152=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): perl-Mail-SpamAssassin-3.4.5-44.13.1 spamassassin-3.4.5-44.13.1 spamassassin-debuginfo-3.4.5-44.13.1 spamassassin-debugsource-3.4.5-44.13.1 - SUSE OpenStack Cloud Crowbar 8 (x86_64): perl-Mail-SpamAssassin-3.4.5-44.13.1 spamassassin-3.4.5-44.13.1 spamassassin-debuginfo-3.4.5-44.13.1 spamassassin-debugsource-3.4.5-44.13.1 - SUSE OpenStack Cloud 9 (x86_64): perl-Mail-SpamAssassin-3.4.5-44.13.1 spamassassin-3.4.5-44.13.1 spamassassin-debuginfo-3.4.5-44.13.1 spamassassin-debugsource-3.4.5-44.13.1 - SUSE OpenStack Cloud 8 (x86_64): perl-Mail-SpamAssassin-3.4.5-44.13.1 spamassassin-3.4.5-44.13.1 spamassassin-debuginfo-3.4.5-44.13.1 spamassassin-debugsource-3.4.5-44.13.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (ppc64le x86_64): perl-Mail-SpamAssassin-3.4.5-44.13.1 spamassassin-3.4.5-44.13.1 spamassassin-debuginfo-3.4.5-44.13.1 spamassassin-debugsource-3.4.5-44.13.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (ppc64le x86_64): perl-Mail-SpamAssassin-3.4.5-44.13.1 spamassassin-3.4.5-44.13.1 spamassassin-debuginfo-3.4.5-44.13.1 spamassassin-debugsource-3.4.5-44.13.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): perl-Mail-SpamAssassin-3.4.5-44.13.1 spamassassin-3.4.5-44.13.1 spamassassin-debuginfo-3.4.5-44.13.1 spamassassin-debugsource-3.4.5-44.13.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (aarch64 ppc64le s390x x86_64): perl-Mail-SpamAssassin-3.4.5-44.13.1 spamassassin-3.4.5-44.13.1 spamassassin-debuginfo-3.4.5-44.13.1 spamassassin-debugsource-3.4.5-44.13.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (aarch64 ppc64le s390x x86_64): perl-Mail-SpamAssassin-3.4.5-44.13.1 spamassassin-3.4.5-44.13.1 spamassassin-debuginfo-3.4.5-44.13.1 spamassassin-debugsource-3.4.5-44.13.1 - SUSE Linux Enterprise Server 12-SP3-BCL (x86_64): perl-Mail-SpamAssassin-3.4.5-44.13.1 spamassassin-3.4.5-44.13.1 spamassassin-debuginfo-3.4.5-44.13.1 spamassassin-debugsource-3.4.5-44.13.1 - SUSE Linux Enterprise Server 12-SP2-LTSS-SAP (x86_64): perl-Mail-SpamAssassin-3.4.5-44.13.1 spamassassin-3.4.5-44.13.1 spamassassin-debuginfo-3.4.5-44.13.1 spamassassin-debugsource-3.4.5-44.13.1 - SUSE Linux Enterprise Server12-SP2-LTSS-ERICSSON (x86_64): perl-Mail-SpamAssassin-3.4.5-44.13.1 spamassassin-3.4.5-44.13.1 spamassassin-debuginfo-3.4.5-44.13.1 spamassassin-debugsource-3.4.5-44.13.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): perl-Mail-SpamAssassin-3.4.5-44.13.1 spamassassin-3.4.5-44.13.1 spamassassin-debuginfo-3.4.5-44.13.1 spamassassin-debugsource-3.4.5-44.13.1 - HPE Helion Openstack 8 (x86_64): perl-Mail-SpamAssassin-3.4.5-44.13.1 spamassassin-3.4.5-44.13.1 spamassassin-debuginfo-3.4.5-44.13.1 spamassassin-debugsource-3.4.5-44.13.1 References: https://www.suse.com/security/cve/CVE-2019-12420.html https://www.suse.com/security/cve/CVE-2020-1946.html https://bugzilla.suse.com/1159133 https://bugzilla.suse.com/1184221 . A crucial release for SpamAssassin resolving significant vulnerabilities has just been made public. Please check and implement the required updates.. SUSE Linux Updates, Spamassassin Security, Critical Updates. . Severity: Important. LinuxSecurity.com Team
SpamAssassin could be made to run programs if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-4899-2 April 12, 2021 spamassassin vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 ESM Summary: SpamAssassin could be made to run programs if it opened a specially crafted file. Software Description: - spamassassin: Perl-based spam filter using text analysis Details: USN-4899-1 fixed a vulnerability in SpamAssassin. This update provides the corresponding update for Ubuntu 14.04 ESM. Original advisory details: Damian Lukowski discovered that SpamAssassin incorrectly handled certain CF files. If a user or automated system were tricked into using a specially- crafted CF file, a remote attacker could possibly run arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM: spamassassin 3.4.2-0ubuntu0.14.04.1+esm3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4899-2 https://ubuntu.com/security/notices/USN-4899-1 CVE-2020-1946 . On February 3, 2022, Ubuntu Security Notice USN-5120-1 addresses a vulnerability in OpenSSL that could lead to unauthorized data exposure.. SpamAssassin Arbitrary Code Ubuntu Security ESM Updates. . Severity: Critical. LinuxSecurity.com Team
Upstream version 3.4.5. See https://lists.apache.org/thread/%
Get the latest Linux and open source security news straight to your inbox.