First published: Mon Jan 13 2020(Updated: )
It was discovered that SpamAssassin incorrectly handled certain CF files. If a user or automated system were tricked into using a specially-crafted CF file, a remote attacker could possibly run arbitrary code. (CVE-2018-11805) It was discovered that SpamAssassin incorrectly handled certain messages. A remote attacker could possibly use this issue to cause SpamAssassin to consume resources, resulting in a denial of service. (CVE-2019-12420)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/spamassassin | <3.4.2-1ubuntu0.19.10.1 | 3.4.2-1ubuntu0.19.10.1 |
Ubuntu Linux | =19.10 | |
All of | ||
ubuntu/spamassassin | <3.4.2-1ubuntu0.19.04.1 | 3.4.2-1ubuntu0.19.04.1 |
Ubuntu Linux | =19.04 | |
All of | ||
ubuntu/spamassassin | <3.4.2-0ubuntu0.18.04.2 | 3.4.2-0ubuntu0.18.04.2 |
Ubuntu Linux | =18.04 | |
All of | ||
ubuntu/spamassassin | <3.4.2-0ubuntu0.16.04.2 | 3.4.2-0ubuntu0.16.04.2 |
Ubuntu Linux | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
USN-4237-1 is classified as a high severity vulnerability due to the potential for remote code execution.
To fix USN-4237-1, you should upgrade SpamAssassin to a version that is not affected, such as 3.4.2-1ubuntu0.19.10.1.
USN-4237-1 affects various versions of SpamAssassin installed on Ubuntu 16.04, 18.04, 19.04, and 19.10.
Yes, USN-4237-1 can be exploited remotely if a user is tricked into using a specially-crafted CF file.
The CVE associated with USN-4237-1 is CVE-2018-11805.