[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250363

 
 

909

 
 

196124

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2020-1341 --- spamassassin

ID: oval:org.secpod.oval:def:1601103Date: (C)2020-01-25   (M)2023-11-10
Class: PATCHFamily: unix




In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publicly. In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we recommend that users should only use update channels or 3rd party .cf files from trusted places

Platform:
Amazon Linux AMI
Product:
spamassassin
Reference:
ALAS-2020-1341
CVE-2019-12420
CVE-2018-11805
CVE    2
CVE-2018-11805
CVE-2019-12420

© SecPod Technologies