vulnerability

FreeBSD: VID-ec04f3d0-8cd9-11eb-bb9f-206a8a720317 (CVE-2020-1946): spamassassin -- Malicious rule configuration (.cf) files can be configured to run system commands

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Mar 24, 2021
Added
Mar 25, 2021
Modified
Dec 10, 2025

Description

The Apache SpamAssassin project reports: Apache SpamAssassin 3.4.5 was recently released [1], and fixes an issue of security note where malicious rule configuration (.cf) files can be configured to run system commands. In Apache SpamAssassin before 3.4.5, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.5, users should only use update channels or 3rd party .cf files from trusted places.

Solution

freebsd-upgrade-package-spamassassin
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.