Protection Mechanism Failure in AMaViS - CVE-2024-28054
Published: March 15, 2024
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to the way Amavis handles emails consisting of multiple parts (`Content-Type: multipart/*`). A remote attacker can create a specially crafted email message that can bypass antivirus scan and deliver potentially dangerous attachments to the end users.
Affected software
Fedora
Ubuntu
amavisd-new (Ubuntu package)
amavis
How to mitigate CVE-2024-28054
amavisd-new (Ubuntu package) - addressed in versions 1:2.11.0-6.1ubuntu1.1, 1:2.12.2-1ubuntu1.1, 1:2.13.0-3ubuntu1.1, 1:2.13.0-3ubuntu2
amavis - addressed in versions 2.12.3-1.el7, 2.13.1-1.el8, 2.13.1-1.el9, 2.13.1-1.fc38, 2.13.1-1.fc39, 2.13.1-1.fc40