Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-1946

Опубликовано: 24 мар. 2021
Источник: redhat
CVSS3: 7.8

Описание

In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, users should only use update channels or 3rd party .cf files from trusted places.

A flaw was found in spamassassin. Malicious rule configuration (.cf) files can be configured to run system commands without any output or errors allowing exploits to be injected in a number of scenarios. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Меры по смягчению последствий

This vulnerability can only be exploited through a malicious rule configuration file. If you are using third-party rule configuration files, it is important to ensure they come only from trusted sources, or are inspected prior to deployment. Even in the absence of this vulnerability, malicious rule configurations could cause significant disruptions to email processed by SpamAssassin.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6spamassassinOut of support scope
Red Hat Enterprise Linux 7spamassassinWill not fix
Red Hat Enterprise Linux 9spamassassinNot affected
Red Hat Enterprise Linux 8spamassassinFixedRHSA-2021:431509.11.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=1943276spamassassin: Malicious rule configuration files can be configured to run system commands

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 4 лет назад

In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, users should only use update channels or 3rd party .cf files from trusted places.

CVSS3: 9.8
nvd
больше 4 лет назад

In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, users should only use update channels or 3rd party .cf files from trusted places.

CVSS3: 9.8
debian
больше 4 лет назад

In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf ...

rocky
около 4 лет назад

Moderate: spamassassin security update

CVSS3: 9.8
github
больше 3 лет назад

In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, users should only use update channels or 3rd party .cf files from trusted places.

7.8 High

CVSS3