cbcvebase.
CVE-2018-11780
published 2018-09-17

CVE-2018-11780: A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.

PriorityP260critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
10.82%
95.4th percentile
A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.

Affected

15 ranges
VendorProductVersion rangeFixed in
apachespamassassin< 3.4.23.4.2
apachespamassassin>= 0 < 3.4.2-13.4.2-1
apachespamassassin>= 0 < 3.4.2-13.4.2-1
apachespamassassin>= 0 < 3.4.2-13.4.2-1
apachespamassassin>= 0 < 3.4.2-13.4.2-1
apachespamassassin>= 0 < 3.4.2-0ubuntu0.14.04.13.4.2-0ubuntu0.14.04.1
apachespamassassin>= 0 < 3.4.2-0ubuntu0.16.04.13.4.2-0ubuntu0.16.04.1
apachespamassassin>= 0 < 3.4.2-0ubuntu0.18.04.13.4.2-0ubuntu0.18.04.1
apache_software_foundationapache_spamassassin
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianspamassassin< spamassassin 3.4.2-1 (bookworm)spamassassin 3.4.2-1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://github.com/apache/spamassassin/commit/c1d8a04661e7ed3da9d58dd19ca23d726333e880#diff-60016dbf9fbe928c87dc724d9e0e883c
  • The vulnerable component is the PDFInfo plugin in Apache SpamAssassin before 3.4.2; detect exploitation attempts by monitoring SpamAssassin processes handling PDF attachments for unexpected child process spawning or shell execution.
  • The PDFInfo plugin is the specific attack surface; environments with this plugin enabled and SpamAssassin < 3.4.2 are at risk of remote code execution via crafted email attachments.
  • ·Red Hat Enterprise Linux 5, 6, and 7 ship versions of SpamAssassin that do not include the PDFInfo plugin, so those platforms are not affected.
  • ·Debian marks the scope of this CVE as 'local', which may affect risk prioritization in Debian-based environments.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.