Executive Summary

Summary
Title SpamAssassin vulnerabilities
Informations
NameUSN-4265-2First vendor Publication2020-02-04
VendorUbuntuLast vendor Modification2020-02-04
Severity (Vendor) N/ARevisionN/A

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base ScoreN/AAttack RangeN/A
Cvss Impact ScoreN/AAttack ComplexityN/A
Cvss Expoit ScoreN/AAuthenticationN/A
Calculate full CVSS 2.0 Vectors scores

Detail

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 ESM - Ubuntu 12.04 ESM

Summary:

Several security issues were fixed in SpamAssassin.

Software Description: - spamassassin: Perl-based spam filter using text analysis

Details:

USN-4265-1 fixed several vulnerabilities in SpamAssassin. This update provides the corresponding update for Ubuntu 12.04 ESM and 14.04 ESM.

Original advisory details:

It was discovered that SpamAssassin incorrectly handled certain CF files.
If a user or automated system were tricked into using a specially-crafted
CF file, a remote attacker could possibly run arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following package versions:

Ubuntu 14.04 ESM:
spamassassin 3.4.2-0ubuntu0.14.04.1+esm2

Ubuntu 12.04 ESM:
spamassassin 3.4.2-0ubuntu0.12.04.4

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4265-2
https://usn.ubuntu.com/4265-1
CVE-2020-1930, CVE-2020-1931

Original Source

Url : http://www.ubuntu.com/usn/USN-4265-2

Alert History

If you want to see full details history, please login or register.
0
DateInformations
2020-02-05 00:18:32
  • First insertion