CVE-2020-1946

Name
CVE-2020-1946
Description
In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, users should only use update channels or 3rd party .cf files from trusted places.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Mailing List https://s.apache.org/3r1wh
DEBIAN https://www.debian.org/security/2021/dsa-4879
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7V2SBVTKVLFFT36ECJQ7TQ7KAQCQZDRZ/
MLIST https://lists.debian.org/debian-lts-announce/2021/04/msg00000.html
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JFBFRIG5TX23NF4ND6OAKKY7I6TLRCCP/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NKAXYBKBMQOLIW6UKASJCAZRBOIYS4RL/
GENTOO https://security.gentoo.org/glsa/202105-26

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:apache:spamassassin:*:*:*:*:*:*:*:* spamassassin >= None < 3.4.5

Vulnerable and fixed packages

Source package Branch Version Maintainer Status