SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-11805

With this, exploits can be injected in a number of scenarios.

MEDIUM 6.7EPSS 0.87%

Does this matter?

Lower severity and a low EPSS score (0.87%). Track it; it rarely justifies an emergency change on its own.

Description

In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we recommend that users should only use update channels or 3rd party .cf files from trusted places.

CVSS 3.1
6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.87% probability · 57th percentile
CISA KEV
Not listed
Weakness
CWE-78
Affected
apache/spamassassin · debian/debian linux
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.