Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-11805

Опубликовано: 12 дек. 2019
Источник: debian
EPSS Низкий

Описание

In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we recommend that users should only use update channels or 3rd party .cf files from trusted places.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
spamassassinfixed3.4.3~rc6-1package

Примечания

  • https://www.openwall.com/lists/oss-security/2019/12/12/1

  • https://markmail.org/message/pyp425yrulfxyhrn

  • https://bz.apache.org/SpamAssassin/show_bug.cgi?id=7648 (not public)

EPSS

Процентиль: 57%
0.00871
Низкий

Связанные уязвимости

CVSS3: 6.7
ubuntu
почти 7 лет назад

In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we recommend that users should only use update channels or 3rd party .cf files from trusted places.

CVSS3: 6.7
redhat
почти 7 лет назад

In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we recommend that users should only use update channels or 3rd party .cf files from trusted places.

CVSS3: 6.7
nvd
почти 7 лет назад

In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we recommend that users should only use update channels or 3rd party .cf files from trusted places.

CVSS3: 6.7
github
больше 4 лет назад

In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we recommend that users should only use update channels or 3rd party .cf files from trusted places.

CVSS3: 6.7
fstec
почти 7 лет назад

Уязвимость программного средства для фильтрации спама Apache SpamAssassin, связанная с отсутствием мер по нейтрализации специальных элементов, позволяющая нарушителю получить несанкционированный доступ к конфиденциальным данным, вызвать отказ в обслуживании и оказать воздействие на целостность данных

EPSS

Процентиль: 57%
0.00871
Низкий