CVE-2018-11781

Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 48%
Affected Products (NVD)
VendorProductVersion
apachespamassassin
𝑥
< 3.4.2
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
16.04
canonicalubuntu_linux
18.04
debiandebian_linux
8.0
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_server_eus
7.5
redhatenterprise_linux_workstation
7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
spamassassin
bookworm
4.0.0-6
fixed
bullseye
3.4.6-1
fixed
sid
4.0.1-2
fixed
trixie
4.0.1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
spamassassin
bionic
Fixed 3.4.2-0ubuntu0.18.04.1
released
cosmic
not-affected
trusty
Fixed 3.4.2-0ubuntu0.14.04.1
released
xenial
Fixed 3.4.2-0ubuntu0.16.04.1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
perl-Mail-SpamAssassin
suse enterprise desktop 15
3.4.2-7.4.1
fixed
suse enterprise desktop 15 SP1
3.4.2-10.19
fixed
suse enterprise desktop 15 SP2
3.4.2-12.5.1
fixed
suse enterprise desktop 15 SP3
3.4.5-12.10.1
fixed
suse enterprise desktop 15 SP4
3.4.5-12.13.1
fixed
suse enterprise desktop 15 SP5
3.4.5-12.13.1
fixed
suse enterprise desktop 15 SP6
3.4.5-150600.23.4
fixed
suse enterprise desktop 15 SP7
3.4.5-150600.23.4
fixed
suse enterprise sap 12 SP4
3.4.2-44.3.1
fixed
suse enterprise sap 12 SP5
3.4.2-44.3.1
fixed
suse enterprise sap 15
3.4.2-7.4.1
fixed
suse enterprise sap 15 SP1
3.4.2-10.19
fixed
suse enterprise sap 15 SP2
3.4.2-12.5.1
fixed
suse enterprise sap 15 SP3
3.4.5-12.10.1
fixed
suse enterprise sap 15 SP4
3.4.5-12.13.1
fixed
suse enterprise sap 15 SP5
3.4.5-12.13.1
fixed
suse enterprise sap 15 SP6
3.4.5-150600.23.4
fixed
suse enterprise sap 15 SP7
3.4.5-150600.23.4
fixed
suse enterprise server 12 SP3
3.4.2-44.3.1
fixed
suse enterprise server 12 SP4
3.4.2-44.3.1
fixed
suse enterprise server 12 SP5
3.4.2-44.3.1
fixed
suse enterprise server 15
3.4.2-7.4.1
fixed
suse enterprise server 15 SP1
3.4.2-10.19
fixed
suse enterprise server 15 SP2
3.4.2-12.5.1
fixed
suse enterprise server 15 SP3
3.4.5-12.10.1
fixed
suse enterprise server 15 SP4
3.4.5-12.13.1
fixed
suse enterprise server 15 SP5
3.4.5-12.13.1
fixed
suse enterprise server 15 SP6
3.4.5-150600.23.4
fixed
suse enterprise server 15 SP7
3.4.5-150600.23.4
fixed
spamassassin
suse enterprise desktop 15
3.4.2-7.4.1
fixed
suse enterprise desktop 15 SP1
3.4.2-10.19
fixed
suse enterprise desktop 15 SP2
3.4.2-12.5.1
fixed
suse enterprise desktop 15 SP3
3.4.5-12.10.1
fixed
suse enterprise desktop 15 SP4
3.4.5-12.13.1
fixed
suse enterprise desktop 15 SP5
3.4.5-12.13.1
fixed
suse enterprise desktop 15 SP6
3.4.5-150600.23.4
fixed
suse enterprise desktop 15 SP7
3.4.5-150600.23.4
fixed
suse enterprise sap 12 SP4
3.4.2-44.3.1
fixed
suse enterprise sap 12 SP5
3.4.2-44.3.1
fixed
suse enterprise sap 15
3.4.2-7.4.1
fixed
suse enterprise sap 15 SP1
3.4.2-10.19
fixed
suse enterprise sap 15 SP2
3.4.2-12.5.1
fixed
suse enterprise sap 15 SP3
3.4.5-12.10.1
fixed
suse enterprise sap 15 SP4
3.4.5-12.13.1
fixed
suse enterprise sap 15 SP5
3.4.5-12.13.1
fixed
suse enterprise sap 15 SP6
3.4.5-150600.23.4
fixed
suse enterprise sap 15 SP7
3.4.5-150600.23.4
fixed
suse enterprise server 12 SP3
3.4.2-44.3.1
fixed
suse enterprise server 12 SP4
3.4.2-44.3.1
fixed
suse enterprise server 12 SP5
3.4.2-44.3.1
fixed
suse enterprise server 15
3.4.2-7.4.1
fixed
suse enterprise server 15 SP1
3.4.2-10.19
fixed
suse enterprise server 15 SP2
3.4.2-12.5.1
fixed
suse enterprise server 15 SP3
3.4.5-12.10.1
fixed
suse enterprise server 15 SP4
3.4.5-12.13.1
fixed
suse enterprise server 15 SP5
3.4.5-12.13.1
fixed
suse enterprise server 15 SP6
3.4.5-150600.23.4
fixed
suse enterprise server 15 SP7
3.4.5-150600.23.4
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
spamassassin
RHEL 7
0:3.4.0-4.el7_5
fixed