CVE-2018-11781

Name
CVE-2018-11781
Description
Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Mailing List https://lists.apache.org/thread.html/7f6a16bc0fd0fd5e67c7fd95bd655069a2ac7d1f88e42d3c853e601c@%3Cannounce.apache.org%3E
Third Party Advisory https://access.redhat.com/errata/RHSA-2018:2916
Third Party Advisory https://usn.ubuntu.com/3811-1/
Mailing List https://lists.debian.org/debian-lts-announce/2018/11/msg00016.html
Third Party Advisory https://usn.ubuntu.com/3811-3/
Third Party Advisory https://security.gentoo.org/glsa/201812-07
SUSE http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00002.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:apache:spamassassin:*:*:*:*:*:*:*:* spamassassin >= None < 3.4.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
spamassassin edge-main 3.4.2-r0 None fixed
spamassassin 3.22-main 3.4.2-r0 None fixed
spamassassin 3.21-main 3.4.2-r0 None fixed
spamassassin 3.20-main 3.4.2-r0 None fixed
spamassassin 3.19-main 3.4.2-r0 None fixed
spamassassin 3.18-main 3.4.2-r0 None fixed
spamassassin 3.17-main 3.4.2-r0 None fixed
spamassassin 3.12-main 3.4.2-r0 None fixed
spamassassin 3.11-main 3.4.2-r0 None fixed
spamassassin 3.10-main 3.4.2-r0 None fixed