Bug 48160 - spamassassin: Multiple issues (4.2)
spamassassin: Multiple issues (4.2)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 4.2
All Linux
: P3 normal (vote)
: UCS 4.2-5-errata
Assigned To: Quality Assurance
Philipp Hahn
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-11-19 08:38 CET by Quality Assurance
Modified: 2018-11-21 15:55 CET (History)
0 users

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score: 8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Quality Assurance univentionstaff 2018-11-19 08:38:08 CET
New Debian spamassassin 3.4.2-0+deb8u1 fixes:
This update addresses the following issues:
* loading of modules from current directory (CVE-2016-1238)
* Certain unclosed tags in crafted emails allow for scan timeouts and result  in denial of service (CVE-2017-15705)
* Potential remote code execution vulnerability in PDFInfo plugin  (CVE-2018-11780)
* Local user code injection in the meta rule syntax (CVE-2018-11781)
Comment 1 Quality Assurance univentionstaff 2018-11-19 09:00:20 CET
--- mirror/ftp/4.2/unmaintained/4.2-0/source/spamassassin_3.4.0-6.dsc
+++ apt/ucs_4.2-0-errata4.2-5/source/spamassassin_3.4.2-0+deb8u1.dsc
@@ -1,3 +1,36 @@
+3.4.2-0+deb8u1 [Tue, 30 Oct 2018 13:28:29 -0400] Antoine Beaupré <anarcat@debian.org>:
+
+  * Non-maintainer upload by the LTS Security Team.
+  * New upstream version to fix several security issues and critical bugs:
+    - CVE-2017-15705: Denial of service issue in which certain unclosed
+      tags in emails cause markup to be handled incorrectly leading to
+      scan timeouts. (Closes: 908969)
+    - CVE-2016-1238: Unsafe usage of "." in @INC in a configuration
+      script.
+    - CVE-2018-11780: potential Remote Code Execution bug with the
+      PDFInfo plugin. (Closes: 908970)
+    - CVE-2018-11781: local user code injection in the meta rule syntax.
+      (Closes: 908971)
+    - BayesStore: bayes_expire table grows, remove_running_expire_tok not
+      called (Closes: 883775)
+    - Fix use of uninitialized variable warning in PDFInfo.pm
+      (Closes: 865924)
+    - Fix "failed to parse plugin" error in
+      Mail::SpamAssassin::Plugin::URILocalBL (Closes: 891041)
+    - SSLv3 support removed from spamc
+  * Don't recursively chown /var/lib/spamassassin during postinst.
+    (Closes: 889501)
+  * Update SysV init script to cope with upstream's change to $0.
+  * Run test suite during build (Closes: #784023).
+  * Refresh patches
+  * Removed patches merged upstream:
+    - 30_edit_README
+    - 35_bug752542-libnet-dns-perl.patch
+    - 97_bug720499-pod-5.18
+    - bug_771408_perl_version
+    - bug_774768_disable_ahbl
+  * Added patch to silence extra debugging messages (Closes: #913571)
+
 3.4.0-6 [Sat, 31 Jan 2015 10:53:22 -0800] Noah Meyerhans <noahm@debian.org>:
 
   * Remove references to ahbl.org DNSBL, which has ceased operation.

<http://10.200.17.11/4.2-5/#5023567469254785785>
Comment 2 Philipp Hahn univentionstaff 2018-11-19 09:29:44 CET
OK: yaml
OK: announce_errata
OK: patch
OK: piuparts

[4.2-5] 8f58592545 Bug #48160: spamassassin 3.4.2-0+deb8u1
 doc/errata/staging/spamassassin.yaml | 20 ++++++++++++++++++++
 1 file changed, 20 insertions(+)
Comment 3 Arvid Requate univentionstaff 2018-11-21 15:55:26 CET
<http://errata.software-univention.de/ucs/4.2/550.html>