VDB

GCVE-VVD-MAGEIA-2019-406

GCVE-VVD-MAGEIA-2019-406
Advisory Published
Vulnetix · Advisory published December 24, 2019
The updated packages fix security vulnerabilities: In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we recommend that users should only use update channels or 3rdparty .cf files from trusted places. (CVE-2018-11805) In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publicly. (CVE-2019-12420)

Affected Products

VendorProductVersionsPlatforms
Mageiaspamassassin0 (affected), 3.4.3-1.mga7 (unaffected)
Mageiaspamassassin-rules0 (affected), 3.4.3-1.mga7 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›