Description:
The SpamAssassin tool provides a way to reduce unsolicited commercial email (spam) from incoming email.
Security Fix(es):
* spamassassin: crafted configuration files can run system commands without any output or errors (CVE-2018-11805)
* spamassassin: crafted email message can lead to DoS (CVE-2019-12420)
* spamassassin: command injection via crafted configuration file (CVE-2020-1930)
* spamassassin: command injection via crafted configuration file (CVE-2020-1931)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
Updated packages:
-
spamassassin-3.4.2-10.el8.x86_64.rpm