First published: Mon Sep 17 2018(Updated: )
A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/spamassassin | 3.4.6-1 4.0.1-1~deb12u1 4.0.1-3 | |
SpamAssassin | <3.4.2 | |
PDFInfo | ||
Ubuntu | =12.04 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11780 has been classified as a potential Remote Code Execution vulnerability, indicating a high severity due to the ability to execute arbitrary code.
To fix CVE-2018-11780, upgrade Apache SpamAssassin to version 3.4.6-1 or later.
Versions of Apache SpamAssassin before 3.4.2 are affected by CVE-2018-11780.
There are no documented workarounds for CVE-2018-11780; updating to a patched version is the recommended approach.
CVE-2018-11780 involves the PDFInfo plugin in Apache SpamAssassin and affects systems running specific versions of SpamAssassin and PDFInfo.