CVE-2018-11781: Code Injection
Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.
Other sources
Apache SpamAssassin before version 3.4.2 is vulnerable to local user code injection in the meta rule syntax.
External Reference:
https://mail-archives.apache.org/modmbox/spamassassin-announce/201809.mbox/raw/%3Cc57c0f41-742c-3c3e-249c-ae2614bf0d7d%40apache.org%3E/
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11781?
CVE-2018-11781 has a high severity rating due to its potential for local code injection.
How do I fix CVE-2018-11781?
To fix CVE-2018-11781, upgrade Apache SpamAssassin to version 3.4.2 or later.
Which versions of Apache SpamAssassin are affected by CVE-2018-11781?
CVE-2018-11781 affects Apache SpamAssassin versions prior to 3.4.2.
Is CVE-2018-11781 a remote or local vulnerability?
CVE-2018-11781 is categorized as a local vulnerability that requires access to the system.
What systems are vulnerable to CVE-2018-11781?
Systems running Apache SpamAssassin versions below 3.4.2 are considered vulnerable to CVE-2018-11781.