• [SECURITY] [DSA 4879-1] spamassassin security update

    From Salvatore Bonaccorso@21:1/5 to All on Sat Mar 27 18:20:01 2021
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4879-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso
    March 27, 2021 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : spamassassin
    CVE ID : CVE-2020-1946
    Debian Bug : 985962

    Damian Lukowski discovered a flaw in spamassassin, a Perl-based spam
    filter using text analysis. Malicious rule configuration files, possibly downloaded from an updates server, could execute arbitrary commands
    under multiple scenarios.

    For the stable distribution (buster), this problem has been fixed in
    version 3.4.2-1+deb10u3.

    We recommend that you upgrade your spamassassin packages.

    For the detailed security status of spamassassin please refer to its
    security tracker page at: https://security-tracker.debian.org/tracker/spamassassin

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: debian-security-announce@lists.debian.org
    -----BEGIN PGP SIGNATURE-----

    iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmBfaMBfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0TMBA/8Dbg7ml7wijsPCctedH70DfmiIlGBXcpwJcDPMv9Qopnn61Pfj6ZoQxWj tvgvxzcf+JgONyme+EdqdqDI/zOPQpmiuCUexBemrUrT/yb4pj4i2Rx4F9Ui5K+5 V3sCQo5rbbOnlJnSqSTx2xBfRqjaLPOL0XvmOWCMQQx44HkRQEfn66Fed8Xte/dh M62dxQ43kQKJEvNj9bOM5YrImSoFNYbFH0W3ub7I1Vsqo++fmHXQczvexOPgcRYF jEANVLEWmqlhyFY3csGBcBoJ6odJLqIWcQ/C4KpXLtfsAKz45MlZxqwtC0mxXnPB 9hKLNFEPaKnws4ANmbSbsumrFV++Ztosm2DI0oXTb7i4kcpcNOjj2k3ybwk/1GFT q/3HAhq4T9oiPb2vLGkWWCQkcC9z1J4dCpI2M3bRewKavSVxV2jB4mx5+eDCVvwM AMbt2SydWWAcDu7qBPurc6MEWLrb+ADSrrpfnvfa6Z4GqVsScAdmT8I2OId6ur3Q JTBOqei1CpM5Q758GJnx5wB1ZDpIXWecdXQRXCqG42YEUki4mHzCXdCvWk3fKt33 V+GdtHLeUMpYRlGpIK2dE8eqjVEoPWDWMo3LoHWk7owVYGjNufrdWLHUZpQz6zdn OSP/eEd5iyo+TBDdAzH2FZdvQlDPBv/XOm5m62rTNmI2UraOebo=
    =FNjo
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)