Oval Definition:oval:org.opensuse.security:def:124884
Revision Date:2019-07-24Version:1
Title:Security update for spamassassin (Important)
Description:

This update for spamassassin to version 3.4.2 fixes the following issues:

Security issues fixed:

- CVE-2017-15705: Fixed denial of service via unclosed tags in crafted emails (bsc#1108745). - CVE-2018-11781: Fixed a code injection in the meta rule syntax by local users (bsc#1108748). - CVE-2018-11780: Fixed a potential remote code execution vulnerability in PDFInfo plugin (bsc#1108750).

Non-security issues fixed:

- Added four new plugins (disabled by default): HashBL, ResourceLimits, FromNameSpoof, Phishing - sa-update script: optional support for SHA-256 / SHA-512 been added for better validation of rules - GeoIP2 support has been added to RelayCountry and URILocalBL plugins - Several new or enhanced configuration options
Family:unixClass:patch
Status:Reference(s):1108745
1108748
1108750
CVE-2016-1238
CVE-2017-15705
CVE-2018-11780
CVE-2018-11781
SUSE-SU-2019:1961-1
Platform(s):SUSE Linux Enterprise Desktop 12 SP4
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP4 is installed
  • AND Package Information
  • perl-Mail-SpamAssassin-3.4.2-44.3.1 is installed
  • OR spamassassin-3.4.2-44.3.1 is installed
  • BACK