CVE-2020-1946: Apache SpamAssassin has an OS Command Injection vulnerability
In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, users should only use update channels or 3rd party .cf files from trusted places.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1946?
The severity of CVE-2020-1946 is considered high due to the potential for system command execution without visible output.
How do I fix CVE-2020-1946?
To fix CVE-2020-1946, upgrade Apache SpamAssassin to version 3.4.5 or later.
Which versions of Apache SpamAssassin are affected by CVE-2020-1946?
CVE-2020-1946 affects Apache SpamAssassin versions prior to 3.4.5.
What vulnerabilities does CVE-2020-1946 introduce?
CVE-2020-1946 introduces the risk of exploits through malicious rule configuration files that can execute system commands.
Are there any specific distributions impacted by CVE-2020-1946?
Yes, Debian and Fedora distributions are affected by CVE-2020-1946 if they use vulnerable versions of Apache SpamAssassin.