First published: Wed Dec 05 2018(Updated: )
USN-3811-1 fixed a vulnerability in spamassassin. This update provides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered that SpamAssassin incorrectly handled the PDFInfo plugin. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2018-11780) It was discovered that SpamAssassin incorrectly handled meta rule syntax. A local attacker could possibly use this issue to execute arbitrary code. (CVE-2018-11781)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/spamassassin | <3.4.2-0ubuntu0.12.04.2 | 3.4.2-0ubuntu0.12.04.2 |
Ubuntu OpenSSH Client | =12.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-3811-3 is categorized as critical due to the potential for remote code execution.
To fix USN-3811-3, update SpamAssassin to version 3.4.2-0ubuntu0.12.04.2 or later on affected Ubuntu systems.
USN-3811-3 addresses a vulnerability in SpamAssassin's handling of the PDFInfo plugin.
USN-3811-3 affects Ubuntu 12.04 LTS systems that use the vulnerable version of SpamAssassin.
There are no specific workarounds for USN-3811-3, and updating to the patched version is recommended.