Описание
Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.
A flaw was found in the way a local user on the SpamAssassin server could inject code in the meta rule syntax. This could cause the arbitrary code execution on the server when these rules are being processed.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | spamassassin | Will not fix | ||
| Red Hat Enterprise Linux 6 | spamassassin | Will not fix | ||
| Red Hat Enterprise Linux 8 | spamassassin | Not affected | ||
| Red Hat Enterprise Linux 7 | spamassassin | Fixed | RHSA-2018:2916 | 11.10.2018 |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=1629536spamassassin: Local user code injection in the meta rule syntax
EPSS
Процентиль: 59%
0.00984
Низкий
8.4 High
CVSS3
Связанные уязвимости
CVSS3: 7.8
ubuntu
почти 8 лет назад
Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.
CVSS3: 7.8
nvd
почти 8 лет назад
Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.
CVSS3: 7.8
debian
почти 8 лет назад
Apache SpamAssassin 3.4.2 fixes a local user code injection in the met ...
CVSS3: 7.8
github
около 4 лет назад
Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.
EPSS
Процентиль: 59%
0.00984
Низкий
8.4 High
CVSS3