CVE-2020-1946

EUVD-2020-12752
In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, users should only use update channels or 3rd party .cf files from trusted places.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 80%
Affected Products (NVD)
VendorProductVersion
apachespamassassin
𝑥
< 3.4.5
debiandebian_linux
9.0
debiandebian_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
spamassassin
bookworm
4.0.0-6
fixed
bullseye
3.4.6-1
fixed
sid
4.0.1-2
fixed
trixie
4.0.1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
spamassassin
bionic
Fixed 3.4.2-0ubuntu0.18.04.5
released
focal
Fixed 3.4.4-1ubuntu1.1
released
groovy
not-affected
trusty
Fixed 3.4.2-0ubuntu0.14.04.1+esm3
released
xenial
Fixed 3.4.2-0ubuntu0.16.04.5
released