CVE-2018-11805

CWE-78OS Command Injection16 documents8 sources
Severity
6.7MEDIUM
EPSS
0.0%
top 91.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 12
Latest updateMay 24

Description

In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we recommend that users should only use update channels or 3rd party .cf files from trusted places.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages5 packages

NVDapache/spamassassin< 3.4.3
CVEListV5apache/apache_spamassassinApache SpamAssassin prior to 3.4.3
Debianspamassassin< 3.4.3~rc6-1+3
Ubuntuspamassassin< 3.4.2-0ubuntu0.16.04.2+2

Also affects: Debian Linux 10.0, 8.0, 9.0

🔴Vulnerability Details

5
GHSA
GHSA-639c-xqgw-3jh5: In Apache SpamAssassin before 32022-05-24
OSV
spamassassin vulnerabilities2020-01-15
OSV
spamassassin vulnerabilities2020-01-13
CVEList
CVE-2018-11805: In Apache SpamAssassin before 32019-12-12
OSV
CVE-2018-11805: In Apache SpamAssassin before 32019-12-12

📋Vendor Advisories

6
Red Hat
spamassassin: command injection via crafted configuration file2020-01-30
Red Hat
spamassassin: command injection via crafted configuration file2020-01-29
Ubuntu
SpamAssassin vulnerabilities2020-01-15
Ubuntu
SpamAssassin vulnerabilities2020-01-13
Red Hat
spamassassin: crafted configuration files can run system commands without any output or errors2019-12-12

💬Community

4
Bugzilla
CVE-2020-1930 spamassassin: command injection via crafted configuration file2020-02-14
Bugzilla
CVE-2020-1931 spamassassin: command injection via crafted configuration file2020-02-14
Bugzilla
CVE-2018-11805 spamassassin: crafted configuration files can run system commands without any output or errors2019-12-18
Bugzilla
CVE-2018-11805 spamassassin: crafted CF files can be configured to run system commands without any output or errors [fedora-all]2019-12-18