LWN.net Logo

spamass-milter: arbitrary code execution

Package(s):spamass-milter CVE #(s):CVE-2010-1132
Created:April 9, 2010 Updated:April 27, 2010
Description: From the Fedora advisory:

This update includes a fix for a problem where if the milter is running using the "-x" option to expand aliases before passing inbound mail through SpamAssassin, a malicious client using a carefully-crafted SMTP session could execute arbitrary code on the mail server. The fix avoids the use of a shell in the alias expansion and hence there is no longer a problem with having to sanitize input from the client.

Alerts:
Debian DSA-2021-2 2010-04-26
Fedora FEDORA-2010-5176 2010-03-23
Fedora FEDORA-2010-5096 2010-03-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds