[CVE-2020-1930] Apache SpamAssassin Nefarious rule configuration (.cf) files can be configured to run system commands

2020-01-29 Thread Kevin A. McGrail
Apache SpamAssassin 3.4.4 was recently released [1], and fixes an issue of security note where nefarious rule configuration (.cf) files can be configured to run system commands similar to CVE-2018-11805.  With this bug unpatched, exploits can be injected in a number of scenarios including the same

[CVE-2020-1931] Apache SpamAssassin Nefarious rule configuration (.cf) files can be configured to run system commands with warnings.

2020-01-29 Thread Kevin A. McGrail
Apache SpamAssassin 3.4.4 was recently released [1], and fixes an issue of security note where nefarious rule configuration (.cf) files can be configured to run system commands similar to CVE-2018-11805.  This issue is less stealthy and attempts to exploit the issue will throw warnings.  Thanks to

Re: [Fuglu-users] fuglu spamassassin bayes users

2020-01-29 Thread Benny Pedersen
Bill Cole skrev den 2020-01-25 21:01: Answering that question requires a more carefully written and detailed problem description. sorry for that

Re: ANNOUNCE: Apache SpamAssassin 3.4.4 available

2020-01-29 Thread Kevin A. McGrail
Correct, it's a policy issue. ASF Projects must stop providing SHA-1 signatures and we negotiated that deadline. Regards, KAM -- Kevin A. McGrail Member, Apache Software Foundation Chair Emeritus Apache SpamAssassin Project https://www.linkedin.com/in/kmcgrail - 703.798.0171 On Wed, Jan 29,

Re: ANNOUNCE: Apache SpamAssassin 3.4.4 available

2020-01-29 Thread John Hardin
On Wed, 29 Jan 2020, Matus UHLAR - fantomas wrote: On 29.01.20 14:12, Kevin A. McGrail wrote: On behalf of the Apache SpamAssassin Project, I am pleased to announce version 3.4.4 is available. Release Notes -- Apache SpamAssassin -- Version 3.4.4 Introduction Apache

Re: ANNOUNCE: Apache SpamAssassin 3.4.4 available

2020-01-29 Thread Matus UHLAR - fantomas
On 29.01.20 14:12, Kevin A. McGrail wrote: On behalf of the Apache SpamAssassin Project, I am pleased to announce version 3.4.4 is available. Release Notes -- Apache SpamAssassin -- Version 3.4.4 Introduction Apache SpamAssassin 3.4.4 is primarily a security release. In this

ANNOUNCE: Apache SpamAssassin 3.4.4 available

2020-01-29 Thread Kevin A. McGrail
On behalf of the Apache SpamAssassin Project, I am pleased to announce version 3.4.4 is available. Release Notes -- Apache SpamAssassin -- Version 3.4.4 Introduction Apache SpamAssassin 3.4.4 is primarily a security release. In this release, there are bug fixes for two CVEs. ***