CVE-2020-1946
Summary
| CVE | CVE-2020-1946 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-25 10:15:00 UTC |
| Updated | 2023-11-07 03:19:00 UTC |
| Description | In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, users should only use update channels or 3rd party .cf files from trusted places. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Spamassassin | All | All | All | All |
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 32 | All | All | All |
| Operating System | Fedoraproject | Fedora | 33 | All | All | All |
| Operating System | Fedoraproject | Fedora | 34 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 32 Update: spamassassin-3.4.5-1.fc32 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 32 Update: spamassassin-3.4.5-1.fc32 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| SpamAssassin: Arbitrary command execution (GLSA 202105-26) — Gentoo security | GENTOO | security.gentoo.org | |
| [SECURITY] Fedora 33 Update: spamassassin-3.4.5-1.fc33 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| Debian -- Security Information -- DSA-4879-1 spamassassin | DEBIAN | www.debian.org | |
| [SECURITY] Fedora 34 Update: spamassassin-3.4.5-1.fc34 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] [DLA 2615-1] spamassassin security update | MLIST | lists.debian.org | |
| [SECURITY] Fedora 34 Update: spamassassin-3.4.5-1.fc34 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [CVE-2020-1946] Apache SpamAssassin malicious rule configuration (.cf) files can be configured to run system commands | MISC | s.apache.org | |
| [SECURITY] Fedora 33 Update: spamassassin-3.4.5-1.fc33 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Apache SpamAssassin would like to thank Damian Lukowski at credativ for ethically reporting this issue.
Legacy QID Mappings
- 159484 Oracle Enterprise Linux Security Update for spamassassin (ELSA-2021-4315)
- 174887 SUSE Enterprise Linux Security Update for spamassassin (SUSE-SU-2021:1152-1)
- 174888 SUSE Enterprise Linux Security Update for spamassassin (SUSE-SU-2021:1153-1)
- 174894 SUSE Enterprise Linux Security Update for spamassassin (SUSE-SU-2021:1163-1)
- 178510 Debian Security Update for spamassassin (DLA 2615-1)
- 178516 Debian Security Update for spamassassin (DSA 4879-1)
- 198317 Ubuntu Security Notification for Spamassassin Vulnerability (USN-4899-1)
- 239834 Red Hat Update for spamassassin (RHSA-2021:4315)
- 281408 Fedora Security Update for spamassassin (FEDORA-2021-90e915cc4f)
- 281409 Fedora Security Update for spamassassin (FEDORA-2021-5a4377797c)
- 281410 Fedora Security Update for spamassassin (FEDORA-2021-bf06dcffa8)
- 352369 Amazon Linux Security Advisory for spamassassin: ALAS2-2021-1642
- 500645 Alpine Linux Security Update for spamassassin
- 504412 Alpine Linux Security Update for spamassassin
- 670224 EulerOS Security Update for spamassassin (EulerOS-SA-2021-1851)
- 670472 EulerOS Security Update for spamassassin (EulerOS-SA-2021-2230)
- 670692 EulerOS Security Update for spamassassin (EulerOS-SA-2021-2450)
- 690198 Free Berkeley Software Distribution (FreeBSD) Security Update for spamassassin (ec04f3d0-8cd9-11eb-bb9f-206a8a720317)
- 710090 Gentoo Linux SpamAssassin Arbitrary command execution vulnerability (GLSA 202105-26)
- 750268 OpenSUSE Security Update for spamassassin (openSUSE-SU-2021:0551-1)
- 940019 AlmaLinux Security Update for spamassassin (ALSA-2021:4315)
- 960685 Rocky Linux Security Update for spamassassin (RLSA-2021:4315)