SUSE-SU-2019:2011-1
Dashboard / Vulnerabilities / SUSE-SU-2019:2011-1
SUSE-SU-2019:2011-1
Summary: Security update for spamassassin
Details: This update for spamassassin to version 3.4.2 fixes the following issues: Security issues fixed: - CVE-2018-11781: Fixed an issue where a local user could inject code in the meta rule syntax (bsc#1108748). - CVE-2018-11780: Fixed a potential remote code execution vulnerability in the PDFInfo plugin (bsc#1108750). - CVE-2017-15705: Fixed a denial of service through unclosed tags in crafted emails (bsc#1108745). - CVE-2016-1238: Fixed an issue where perl would load modules from the current directory (bsc#1108749). Non-security issues fixed: - Use systemd timers instead of cron (bsc#1115411) - Fixed incompatibility with Net::DNS >= 1.01 (bsc#1107765) - Fixed warning about deprecated regex during sa-update (bsc#1069831)
References: https://www.suse.com/support/update/announcement/2019/suse-su-20192011-1/, https://bugzilla.suse.com/1069831, https://bugzilla.suse.com/1107765, https://bugzilla.suse.com/1108745, https://bugzilla.suse.com/1108748, https://bugzilla.suse.com/1108749, https://bugzilla.suse.com/1108750, https://bugzilla.suse.com/1115411, https://www.suse.com/security/cve/CVE-2016-1238, https://www.suse.com/security/cve/CVE-2017-15705, https://www.suse.com/security/cve/CVE-2018-11780, https://www.suse.com/security/cve/CVE-2018-11781
Affected packages
Package
Name: spamassassin
Purl: pkg:rpm/suse/spamassassin&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015
Affected ranges
Type: ECOSYSTEM
Events:
