CVE-2018-11780: Code Injection
Published Sep 17, 2018
·Updated
A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.
Affected Software
8 affected componentsFixes available
Apache SpamAssassin<3.4.2
Pdfinfo Project Pdfinfo
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Debian Debian Linux=8.0
debian/spamassassin
3.4.6-14.0.1-1~deb12u14.0.1-54.0.2-4
Event History
Sep 17, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Feb 19, 2026
Data Sourced
via Ubuntu·09:28 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·09:28 PM
Description
Feb 28, 2026
Data Sourced
via Debian·09:34 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-11780?
CVE-2018-11780 has been classified as a potential Remote Code Execution vulnerability, indicating a high severity due to the ability to execute arbitrary code.
2
How do I fix CVE-2018-11780?
To fix CVE-2018-11780, upgrade Apache SpamAssassin to version 3.4.6-1 or later.
3
Which versions of Apache SpamAssassin are affected by CVE-2018-11780?
Versions of Apache SpamAssassin before 3.4.2 are affected by CVE-2018-11780.
4
Is there a workaround for CVE-2018-11780?
There are no documented workarounds for CVE-2018-11780; updating to a patched version is the recommended approach.
5
What software components are involved in CVE-2018-11780?
CVE-2018-11780 involves the PDFInfo plugin in Apache SpamAssassin and affects systems running specific versions of SpamAssassin and PDFInfo.