Bugzilla – Bug 1108750
VUL-0: CVE-2018-11780: spamassassin: Potential remote code execution vulnerability in PDFInfo plugin
Last modified: 2022-05-16 06:32:58 UTC
rh#1629532 A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2. References: https://bugzilla.redhat.com/show_bug.cgi?id=1629532 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-11780 http://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-11780.html
SUSE-SU-2019:1961-1: An update that fixes four vulnerabilities is now available. Category: security (important) Bug References: 1108745,1108748,1108750 CVE References: CVE-2016-1238,CVE-2017-15705,CVE-2018-11780,CVE-2018-11781 Sources used: SUSE Linux Enterprise Server 12-SP4 (src): spamassassin-3.4.2-44.3.1 SUSE Linux Enterprise Desktop 12-SP4 (src): spamassassin-3.4.2-44.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2019:2011-1: An update that solves four vulnerabilities and has three fixes is now available. Category: security (moderate) Bug References: 1069831,1107765,1108745,1108748,1108749,1108750,1115411 CVE References: CVE-2016-1238,CVE-2017-15705,CVE-2018-11780,CVE-2018-11781 Sources used: SUSE Linux Enterprise Module for Development Tools 15 (src): spamassassin-3.4.2-7.4.1 SUSE Linux Enterprise Module for Basesystem 15 (src): spamassassin-3.4.2-7.4.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2019:1831-1: An update that solves four vulnerabilities and has three fixes is now available. Category: security (moderate) Bug References: 1069831,1107765,1108745,1108748,1108749,1108750,1115411 CVE References: CVE-2016-1238,CVE-2017-15705,CVE-2018-11780,CVE-2018-11781 Sources used: openSUSE Leap 15.0 (src): spamassassin-3.4.2-lp150.6.3.1
fixed
@Peter, could you please submit to SUSE:SLE-11-SP1:Update? :)
(In reply to Thomas Leroy from comment #6) > @Peter, could you please submit to SUSE:SLE-11-SP1:Update? :) Not neccessary. Version 3.3.1 does not contains the plugin PDFInfo.pm
(In reply to Peter Varkoly from comment #7) > (In reply to Thomas Leroy from comment #6) > > @Peter, could you please submit to SUSE:SLE-11-SP1:Update? :) > > Not neccessary. Version 3.3.1 does not contains the plugin PDFInfo.pm Great, thanks Peter!