CVE-2018-11805
spamassassin: crafted configuration files can run system commands without any output or errors
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we recommend that users should only use update channels or 3rd party .cf files from trusted places.
En Apache SpamAssassin versiones anteriores a 3.4.3, se pueden configurar archivos CF nefastos para ejecutar comandos de sistema sin ningún resultado o error. Con esto, las explotaciones pueden ser inyectadas en varios escenarios. Adicionalmente para actualizar a SA versión 3.4.3, recomendamos que los usuarios solo utilicen canales de actualización o archivos .cf de terceros desde lugares confiables.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-06-05 CVE Reserved
- 2019-12-12 CVE Published
- 2024-08-05 CVE Updated
- 2024-10-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (30)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00003.html | 2023-11-07 | |
https://svn.apache.org/repos/asf/spamassassin/branches/3.4/build/announcements/3.4.3.txt | 2023-11-07 | |
https://usn.ubuntu.com/4237-1 | 2023-11-07 | |
https://usn.ubuntu.com/4237-2 | 2023-11-07 | |
https://www.debian.org/security/2019/dsa-4584 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2018-11805 | 2020-11-04 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1784974 | 2020-11-04 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Spamassassin Search vendor "Apache" for product "Spamassassin" | < 3.4.3 Search vendor "Apache" for product "Spamassassin" and version " < 3.4.3" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 10.0 Search vendor "Debian" for product "Debian Linux" and version "10.0" | - |
Affected
|