In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, users should only use update channels or 3rd party .cf files from trusted places.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1946
Reference (s):
- DEBIAN:DSA-4879
- URL: https://www.debian.org/security/2021/dsa-4879
- FEDORA:FEDORA-2021-5a4377797c
- URL: https://lists.fedoraproject.org/archives/list/[email protected]/message/NKAXYBKBMQOLIW6UKASJCAZRBOIYS4RL/
- FEDORA:FEDORA-2021-90e915cc4f

