CVE-2018-11780

A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
Affected Products (NVD)
VendorProductVersion
apachespamassassin
𝑥
< 3.4.2
pdfinfo_projectpdfinfo
-
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
16.04
canonicalubuntu_linux
18.04
debiandebian_linux
8.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
spamassassin
bookworm
4.0.0-6
fixed
bullseye
3.4.6-1
fixed
sid
4.0.1-2
fixed
trixie
4.0.1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
spamassassin
bionic
Fixed 3.4.2-0ubuntu0.18.04.1
released
cosmic
not-affected
trusty
Fixed 3.4.2-0ubuntu0.14.04.1
released
xenial
Fixed 3.4.2-0ubuntu0.16.04.1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
perl-Mail-SpamAssassin
suse enterprise desktop 15
3.4.2-7.4.1
fixed
suse enterprise desktop 15 SP1
3.4.2-10.19
fixed
suse enterprise desktop 15 SP2
3.4.2-12.5.1
fixed
suse enterprise desktop 15 SP3
3.4.5-12.10.1
fixed
suse enterprise desktop 15 SP4
3.4.5-12.13.1
fixed
suse enterprise desktop 15 SP5
3.4.5-12.13.1
fixed
suse enterprise desktop 15 SP6
3.4.5-150600.23.4
fixed
suse enterprise desktop 15 SP7
3.4.5-150600.23.4
fixed
suse enterprise sap 12 SP4
3.4.2-44.3.1
fixed
suse enterprise sap 12 SP5
3.4.2-44.3.1
fixed
suse enterprise sap 15
3.4.2-7.4.1
fixed
suse enterprise sap 15 SP1
3.4.2-10.19
fixed
suse enterprise sap 15 SP2
3.4.2-12.5.1
fixed
suse enterprise sap 15 SP3
3.4.5-12.10.1
fixed
suse enterprise sap 15 SP4
3.4.5-12.13.1
fixed
suse enterprise sap 15 SP5
3.4.5-12.13.1
fixed
suse enterprise sap 15 SP6
3.4.5-150600.23.4
fixed
suse enterprise sap 15 SP7
3.4.5-150600.23.4
fixed
suse enterprise server 12 SP3
3.4.2-44.3.1
fixed
suse enterprise server 12 SP4
3.4.2-44.3.1
fixed
suse enterprise server 12 SP5
3.4.2-44.3.1
fixed
suse enterprise server 15
3.4.2-7.4.1
fixed
suse enterprise server 15 SP1
3.4.2-10.19
fixed
suse enterprise server 15 SP2
3.4.2-12.5.1
fixed
suse enterprise server 15 SP3
3.4.5-12.10.1
fixed
suse enterprise server 15 SP4
3.4.5-12.13.1
fixed
suse enterprise server 15 SP5
3.4.5-12.13.1
fixed
suse enterprise server 15 SP6
3.4.5-150600.23.4
fixed
suse enterprise server 15 SP7
3.4.5-150600.23.4
fixed
spamassassin
suse enterprise desktop 15
3.4.2-7.4.1
fixed
suse enterprise desktop 15 SP1
3.4.2-10.19
fixed
suse enterprise desktop 15 SP2
3.4.2-12.5.1
fixed
suse enterprise desktop 15 SP3
3.4.5-12.10.1
fixed
suse enterprise desktop 15 SP4
3.4.5-12.13.1
fixed
suse enterprise desktop 15 SP5
3.4.5-12.13.1
fixed
suse enterprise desktop 15 SP6
3.4.5-150600.23.4
fixed
suse enterprise desktop 15 SP7
3.4.5-150600.23.4
fixed
suse enterprise sap 12 SP4
3.4.2-44.3.1
fixed
suse enterprise sap 12 SP5
3.4.2-44.3.1
fixed
suse enterprise sap 15
3.4.2-7.4.1
fixed
suse enterprise sap 15 SP1
3.4.2-10.19
fixed
suse enterprise sap 15 SP2
3.4.2-12.5.1
fixed
suse enterprise sap 15 SP3
3.4.5-12.10.1
fixed
suse enterprise sap 15 SP4
3.4.5-12.13.1
fixed
suse enterprise sap 15 SP5
3.4.5-12.13.1
fixed
suse enterprise sap 15 SP6
3.4.5-150600.23.4
fixed
suse enterprise sap 15 SP7
3.4.5-150600.23.4
fixed
suse enterprise server 12 SP3
3.4.2-44.3.1
fixed
suse enterprise server 12 SP4
3.4.2-44.3.1
fixed
suse enterprise server 12 SP5
3.4.2-44.3.1
fixed
suse enterprise server 15
3.4.2-7.4.1
fixed
suse enterprise server 15 SP1
3.4.2-10.19
fixed
suse enterprise server 15 SP2
3.4.2-12.5.1
fixed
suse enterprise server 15 SP3
3.4.5-12.10.1
fixed
suse enterprise server 15 SP4
3.4.5-12.13.1
fixed
suse enterprise server 15 SP5
3.4.5-12.13.1
fixed
suse enterprise server 15 SP6
3.4.5-150600.23.4
fixed
suse enterprise server 15 SP7
3.4.5-150600.23.4
fixed