cbcvebase.
CVE-2019-12420
published 2019-12-12

CVE-2019-12420: In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publicly.

Affected

13 ranges
VendorProductVersion rangeFixed in
apacheapache_spamassassin
apachespamassassin< 3.4.33.4.3
apachespamassassin>= 0 < 3.4.3~rc6-13.4.3~rc6-1
apachespamassassin>= 0 < 3.4.3~rc6-13.4.3~rc6-1
apachespamassassin>= 0 < 3.4.3~rc6-13.4.3~rc6-1
apachespamassassin>= 0 < 3.4.3~rc6-13.4.3~rc6-1
apachespamassassin>= 0 < 3.4.2-0ubuntu0.16.04.23.4.2-0ubuntu0.16.04.2
apachespamassassin>= 0 < 3.4.2-0ubuntu0.18.04.23.4.2-0ubuntu0.18.04.2
apachespamassassin>= 0 < 3.4.2-0ubuntu0.14.04.1+esm13.4.2-0ubuntu0.14.04.1+esm1
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianspamassassin< spamassassin 3.4.3~rc6-1 (bookworm)spamassassin 3.4.3~rc6-1 (bookworm)

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH