#VU16310 Improper input validation in SpamAssassin - CVE-2018-11780
Published: December 5, 2018 / Updated: December 6, 2018
SpamAssassin
Apache Foundation
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a remote code execution bug in the PDFInfo plug-in when handling malicious input. A remote unauthenticated attacker can trick the victim into opening a specially crafted email message and execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.