OPENSUSE-SU-2019:1831-1

Advisory lineage Upstream: 4 Downstream: 0
Published: 06 Aug 2019, 15:40
Last modified:04 Feb 2026, 04:27

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

06 Aug 2019, 15:40
Published
Vulnerability first disclosed
04 Feb 2026, 04:27
Last Modified
Vulnerability information updated

Description

Security update for spamassassin This update for spamassassin to version 3.4.2 fixes the following issues: Security issues fixed: - CVE-2018-11781: Fixed an issue where a local user could inject code in the meta rule syntax (bsc#1108748). - CVE-2018-11780: Fixed a potential remote code execution vulnerability in the PDFInfo plugin (bsc#1108750). - CVE-2017-15705: Fixed a denial of service through unclosed tags in crafted emails (bsc#1108745). - CVE-2016-1238: Fixed an issue where perl would load modules from the current directory (bsc#1108749). Non-security issues fixed: - Use systemd timers instead of cron (bsc#1115411) - Fixed incompatibility with Net::DNS >= 1.01 (bsc#1107765) - Fixed warning about deprecated regex during sa-update (bsc#1069831) This update was imported from the SUSE:SLE-15:Update update project.

Affected Systems

  • opensusespamassassin&distro=openSUSE Leap 15.0

    < 3.4.2-lp150.6.3.1

References (12)