OS Command Injection in SpamAssassin - CVE-2020-1946
Published: March 24, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation when processing rule configuration (.cf) files. A remote authenticated attacker trick the victim use a specially crafted rule configuration file and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
HPE Helion Openstack
Red Hat Enterprise Linux for ARM 64
SUSE OpenStack Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Development Tools
Fedora
spamassassin (Alpine package)
spamassassin (Debian package)
perl-Mail-SpamAssassin-Plugin-iXhash2
spamassassin (Ubuntu package)
spamassassin (Red Hat package)
spamassassin
spamassassin-debugsource
spamassassin-debuginfo
perl-Mail-SpamAssassin
How to mitigate CVE-2020-1946
spamassassin (Debian package) - update to 3.4.2-1+deb10u3
perl-Mail-SpamAssassin-Plugin-iXhash2 - addressed in versions 2.05-7.14.1, 2.05-12.10.1
spamassassin (Ubuntu package) - addressed in versions 3.4.2-0ubuntu0.14.04.1+esm3, 3.4.2-0ubuntu0.16.04.5, 3.4.2-0ubuntu0.18.04.5, 3.4.4-1ubuntu1.1
spamassassin (Red Hat package) - update to 3.4.4-4.el8
spamassassin - addressed in versions 3.4.5-1.fc32, 3.4.5-1.fc33, 3.4.5-1.fc34
spamassassin-debugsource - addressed in versions 3.4.5-7.14.1, 3.4.5-12.10.1, 3.4.5-44.13.1
spamassassin-debuginfo - addressed in versions 3.4.5-7.14.1, 3.4.5-12.10.1, 3.4.5-44.13.1
spamassassin - addressed in versions 3.4.5-7.14.1, 3.4.5-12.10.1, 3.4.5-44.13.1
perl-Mail-SpamAssassin - addressed in versions 3.4.5-7.14.1, 3.4.5-12.10.1, 3.4.5-44.13.1
External References
Related Security Bulletins
- OS command injection in Apache SpamAssassin
- Debian update for spamassassin
- OS Command Injection in spamassassin (Alpine package)
- Gentoo update for SpamAssassin
- SUSE update for spamassassin
- SUSE update for spamassassin
- SUSE update for spamassassin
- Ubuntu update for spamassassin
- Ubuntu update for spamassassin
- Red Hat Enterprise Linux 8 update for spamassassin
- Fedora 34 update for spamassassin
- Fedora 32 update for spamassassin
- Fedora 33 update for spamassassin