OS Command Injection in SpamAssassin - CVE-2018-11805

 

OS Command Injection in SpamAssassin - CVE-2018-11805

Published: December 13, 2019


Vulnerability identifier: #VU23601
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11805
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary shell commands on the target system.

The vulnerability exists due to nefarious CF files can be configured to run system commands without any output. A local user can inject arbitrary commands into nefarious CF files and compromise the system or execute arbitrary code with elevated privileges.


Affected software

SpamAssassin
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Opensuse
spamassassin (Alpine package)
spamassassin (Debian package)
spamassassin (Ubuntu package)
spamassassin (Red Hat package)

How to mitigate CVE-2018-11805

Install updates from vendor's website.

SpamAssassin - update to 3.4.3
spamassassin (Alpine package) - update to 3.4.3-r0
spamassassin (Debian package) - addressed in versions 3.4.2-1+deb10u1, 3.4.2-1~deb9u2
spamassassin (Ubuntu package) - addressed in versions 3.4.2-0ubuntu0.16.04.2, 3.4.2-0ubuntu0.18.04.2, 3.4.2-1ubuntu0.19.04.1, 3.4.2-1ubuntu0.19.10.1
spamassassin (Red Hat package) - update to 3.4.2-10.el8

External References

Related Security Bulletins