CVE-2020-1946
published 2021-03-25CVE-2020-1946: In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this…
PriorityP358critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.13%
92.6th percentile
In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, users should only use update channels or 3rd party .cf files from trusted places.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | spamassassin | < 3.4.5 | 3.4.5 |
| apache | spamassassin | >= 0 < 3.4.5~pre1-1 | 3.4.5~pre1-1 |
| apache | spamassassin | >= 0 < 3.4.5~pre1-1 | 3.4.5~pre1-1 |
| apache | spamassassin | >= 0 < 3.4.5~pre1-1 | 3.4.5~pre1-1 |
| apache | spamassassin | >= 0 < 3.4.5~pre1-1 | 3.4.5~pre1-1 |
| apache_software_foundation | apache_spamassassin | >= Apache SpamAssassin < 3.4.5 | 3.4.5 |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | spamassassin | < spamassassin 3.4.5~pre1-1 (bookworm) | spamassassin 3.4.5~pre1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
SpamAssassin vulnerability
vendor_ubuntu·2021-04-12
CVE-2020-1946 SpamAssassin vulnerability
Title: SpamAssassin vulnerability
Summary: SpamAssassin could be made to run programs if it opened a specially crafted
file.
USN-4899-1 fixed a vulnerability in SpamAssassin. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
Damian Lukowski discovered that SpamAssassin incorrectly handled certain CF
files. If a user or automated system were tricked into using a specially-
crafted CF file, a remote attacker could possibly run arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
SpamAssassin vulnerability
vendor_ubuntu·2021-04-01
CVE-2020-1946 SpamAssassin vulnerability
Title: SpamAssassin vulnerability
Summary: SpamAssassin could be made to run programs if it opened a specially crafted
file.
Damian Lukowski discovered that SpamAssassin incorrectly handled certain CF
files. If a user or automated system were tricked into using a specially-
crafted CF file, a remote attacker could possibly run arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
spamassassin: Malicious rule configuration files can be configured to run system commands
vendor_redhat·2021-03-24·CVSS 9.8
CVE-2020-1946 [CRITICAL] CWE-77 spamassassin: Malicious rule configuration files can be configured to run system commands
spamassassin: Malicious rule configuration files can be configured to run system commands
In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, users should only use update channels or 3rd party .cf files from trusted places.
A flaw was found in spamassassin. Malicious rule configuration (.cf) files can be configured to run system commands without any output or errors allowing exploits to be injected in a number of scenarios. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Mitigation: This vulnerability can only be explo
Debian
CVE-2020-1946: spamassassin - In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files ca...
vendor_debian·2020·CVSS 9.8
CVE-2020-1946 [CRITICAL] CVE-2020-1946: spamassassin - In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files ca...
In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, users should only use update channels or 3rd party .cf files from trusted places.
Scope: local
bookworm: resolved (fixed in 3.4.5~pre1-1)
bullseye: resolved (fixed in 3.4.5~pre1-1)
forky: resolved (fixed in 3.4.5~pre1-1)
sid: resolved (fixed in 3.4.5~pre1-1)
trixie: resolved (fixed in 3.4.5~pre1-1)
GHSA
GHSA-qmmx-pr2m-q429: In Apache SpamAssassin before 3
ghsa_unreviewed·2022-05-24
CVE-2020-1946 [CRITICAL] CWE-78 GHSA-qmmx-pr2m-q429: In Apache SpamAssassin before 3
In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, users should only use update channels or 3rd party .cf files from trusted places.
OSV
CVE-2020-1946: In Apache SpamAssassin before 3
osv·2021-03-25·CVSS 9.8
CVE-2020-1946 [CRITICAL] CVE-2020-1946: In Apache SpamAssassin before 3
In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, users should only use update channels or 3rd party .cf files from trusted places.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2021/04/msg00000.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7V2SBVTKVLFFT36ECJQ7TQ7KAQCQZDRZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JFBFRIG5TX23NF4ND6OAKKY7I6TLRCCP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NKAXYBKBMQOLIW6UKASJCAZRBOIYS4RL/https://s.apache.org/3r1whhttps://security.gentoo.org/glsa/202105-26https://www.debian.org/security/2021/dsa-4879https://lists.debian.org/debian-lts-announce/2021/04/msg00000.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7V2SBVTKVLFFT36ECJQ7TQ7KAQCQZDRZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JFBFRIG5TX23NF4ND6OAKKY7I6TLRCCP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NKAXYBKBMQOLIW6UKASJCAZRBOIYS4RL/https://s.apache.org/3r1whhttps://security.gentoo.org/glsa/202105-26https://www.debian.org/security/2021/dsa-4879
2021-03-25
Published