QID 198317

Date Published: 2021-04-06

QID 198317: Ubuntu Security Notification for Spamassassin Vulnerability (USN-4899-1)

It was discovered that SpamAssassin incorrectly handled certain CF files.

If a user or automated system were tricked into using a specially- crafted CF file, a remote attacker could possibly run arbitrary code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Refer to Ubuntu advisory USN-4899-1 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 198317

    Software Advisories
    Advisory ID Software Component Link
    USN-4899-1 16.04 (Xenial) on src spamassassin URL Logo launchpad.net/ubuntu/+source/spamassassin/3.4.2-0ubuntu0.16.04.5
    USN-4899-1 18.04 (bionic) on src spamassassin URL Logo launchpad.net/ubuntu/+source/spamassassin/3.4.2-0ubuntu0.18.04.5
    USN-4899-1 20.04 (focal) on src spamassassin URL Logo launchpad.net/ubuntu/+source/spamassassin/3.4.4-1ubuntu1.1