vulnerability
FreeBSD: VID-ec04f3d0-8cd9-11eb-bb9f-206a8a720317 (CVE-2020-1946): spamassassin -- Malicious rule configuration (.cf) files can be configured to run system commands
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 10 | (AV:N/AC:L/Au:N/C:C/I:C/A:C) | Mar 24, 2021 | Mar 25, 2021 | Dec 10, 2025 |
Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Mar 24, 2021
Added
Mar 25, 2021
Modified
Dec 10, 2025
Description
The Apache SpamAssassin project reports: Apache SpamAssassin 3.4.5 was recently released [1], and fixes an issue of security note where malicious rule configuration (.cf) files can be configured to run system commands. In Apache SpamAssassin before 3.4.5, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.5, users should only use update channels or 3rd party .cf files from trusted places.
Solution
freebsd-upgrade-package-spamassassin
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.