Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2021-4315

Опубликовано: 16 нояб. 2021
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2021-4315: spamassassin security update (MODERATE)

[3.4.4-4.el4]

  • Fix header parsing

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

spamassassin

3.4.4-4.el8

Oracle Linux x86_64

spamassassin

3.4.4-4.el8

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 4 лет назад

In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, users should only use update channels or 3rd party .cf files from trusted places.

CVSS3: 7.8
redhat
больше 4 лет назад

In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, users should only use update channels or 3rd party .cf files from trusted places.

CVSS3: 9.8
nvd
больше 4 лет назад

In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, users should only use update channels or 3rd party .cf files from trusted places.

CVSS3: 9.8
debian
больше 4 лет назад

In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf ...

rocky
около 4 лет назад

Moderate: spamassassin security update