VDB
GCVE-VVD-MAGEIA-2019-406
GCVE-VVD-MAGEIA-2019-406
Advisory Published
The updated packages fix security vulnerabilities:
In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured
to run system commands without any output or errors. With this, exploits
can be injected in a number of scenarios. In addition to upgrading to SA
3.4.3, we recommend that users should only use update channels or 3rdparty
.cf files from trusted places. (CVE-2018-11805)
In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to
use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the
recommended fix but details will not be shared publicly. (CVE-2019-12420)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | spamassassin | 0 (affected), 3.4.3-1.mga7 (unaffected) | — |
| Mageia | spamassassin-rules | 0 (affected), 3.4.3-1.mga7 (unaffected) | — |
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.