OS Command Injection in SpamAssassin - CVE-2018-11805
Published: December 13, 2019
Vulnerability details
The vulnerability allows a local user to execute arbitrary shell commands on the target system.
The vulnerability exists due to nefarious CF files can be configured to run system commands without any output. A local user can inject arbitrary commands into nefarious CF files and compromise the system or execute arbitrary code with elevated privileges.
Affected software
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Opensuse
spamassassin (Alpine package)
spamassassin (Debian package)
spamassassin (Ubuntu package)
spamassassin (Red Hat package)
How to mitigate CVE-2018-11805
spamassassin (Alpine package) - update to 3.4.3-r0
spamassassin (Debian package) - addressed in versions 3.4.2-1+deb10u1, 3.4.2-1~deb9u2
spamassassin (Ubuntu package) - addressed in versions 3.4.2-0ubuntu0.16.04.2, 3.4.2-0ubuntu0.18.04.2, 3.4.2-1ubuntu0.19.04.1, 3.4.2-1ubuntu0.19.10.1
spamassassin (Red Hat package) - update to 3.4.2-10.el8
External References
- http://www.openwall.com/lists/oss-security/2019/12/12/1
- https://bz.apache.org/SpamAssassin/show_bug.cgi?id=7647
- https://lists.apache.org/thread.html/2946b38caec47f7f6a79e8e03d2aa723794186e59a7dc6b5e76dfc18@%3Cannounce.spamassassin.apache.org%3E
- https://lists.apache.org/thread.html/6f89f82a573ea616dce53ec67e52d963618a9f9ac71da5c1efdbd166@%3Cusers.spamassassin.apache.org%3E
- https://lists.apache.org/thread.html/bc58907171c6585e5875a3ce86066d4956c218911cb74e3156de4433@%3Cannounce.apache.org%3E
- https://lists.apache.org/thread.html/d015dc5b4f24fd6777a85d068502a9c5d58d69d877ed5b0eb9a22cd5@%3Cdev.spamassassin.apache.org%3E
- https://seclists.org/oss-sec/2019/q4/154
- https://svn.apache.org/repos/asf/spamassassin/branches/3.4/build/announcements/3.4.3.txt