CVE-2020-1946

CRITICAL

Apache SpamAssassin < 3.4.5 - OS Command Injection via Rule Configuration Files

Title source: llm
STIX 2.1

Description

In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, users should only use update channels or 3rd party .cf files from trusted places.

References (7)

Core 7
Core References
Mailing List, Vendor Advisory x_refsource_misc
https://s.apache.org/3r1wh
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2021/dsa-4879
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2021/04/msg00000.html
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202105-26

Scores

CVSS v3 9.8
EPSS 0.0149
EPSS Percentile 81.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (6)
apache/spamassassin < 3.4.5
debian/debian_linux 9.0
debian/debian_linux 10.0
fedoraproject/fedora 32
fedoraproject/fedora 33
fedoraproject/fedora 34
Published Mar 25, 2021
Tracked Since Feb 18, 2026