openSUSE-SU-2019:0297-1

    Dashboard / Vulnerabilities / openSUSE-SU-2019:0297-1

    openSUSE-SU-2019:0297-1

    Published: 23 Mar 2019Last Modified: 4 Feb 2026
    Upstream:
    Aliases:

    Summary: Security update for amavisd-new

    Details: This update for amavisd-new fixes the following issues: Security issue fixed: - CVE-2016-1238: Workedaround a perl vulnerability by removing a trailing dot element from @INC (bsc#987887). Other issues addressed: - update to version 2.11.1 (bsc#1123389). - amavis-services: bumping up syslog level from LOG_NOTICE to LOG_ERR for a message 'PID <pid> went away', and removed redundant newlines from some log messages - avoid warning messages 'Use of uninitialized value in subroutine entry' in Encode::MIME::Header when the $check argument is undefined - @sa_userconf_maps has been extended to allow loading of per-recipient (or per-policy bank, or global) SpamAssassin configuration set from LDAP. For consistency with SQL a @sa_userconf_maps entry prefixed with 'ldap:' will load SpamAssassin configuration set using the load_scoreonly_ldap() method. - add some Sanesecurity.Foxhole false positives to the default list @virus_name_to_spam_score_maps - update amavis-milter to version 2.6.1: * Fixed a bug when creating amavisd-new policy bank names This update was imported from the SUSE:SLE-15:Update update project.

    Affected packages

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High