spamassassin: CVE-2019-12420: specially crafted messages can exhaust system resources resulting in a denial of service

Related Vulnerabilities: CVE-2019-12420  

Debian Bug report logs - #946653
spamassassin: CVE-2019-12420: specially crafted messages can exhaust system resources resulting in a denial of service

version graph

Reported by: Noah Meyerhans <noahm@debian.org>

Date: Thu, 12 Dec 2019 21:09:02 UTC

Severity: grave

Tags: fixed-upstream, pending, security, upstream

Found in versions spamassassin/3.4.2-1~deb9u1, spamassassin/3.4.2-1

Fixed in version 3.4.3~rc6-1

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org:
Bug#946653; Package spamassassin. (Thu, 12 Dec 2019 21:09:04 GMT) (full text, mbox, link).


Acknowledgement sent to Noah Meyerhans <noahm@debian.org>:
New Bug report received and forwarded. (Thu, 12 Dec 2019 21:09:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Noah Meyerhans <noahm@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: spamassassin: specially crafted messages can exhaust system resources resulting in a denial of service
Date: Thu, 12 Dec 2019 16:06:49 -0500
Package: spamassassin
Version: 3.4.2-1
Severity: grave
Tags: upstream fixed-upstream pending security

Per upstream's 3.4.3 release announcement:

Apache SpamAssassin 3.4.3 was recently released [1], and fixes an issue
of security note where a message can be crafted in a way to use
excessive resources.  Upgrading to SA 3.4.3 as soon as possible is the
recommended fix but details will not be shared publicly. Thanks to Joran
Dirk Greef, Ronomon, Cape Town for reporting the issue.

This issue has been assigned CVE id CVE-2019-12420 [2]

To contact the Apache SpamAssassin security team, please e-mail
security at spamassassin.apache.org.  For more information about Apache
SpamAssassin, visit the http://spamassassin.apache.org/ web site.

Apache SpamAssassin Security Team

[1]:
https://svn.apache.org/repos/asf/spamassassin/branches/3.4/build/announcements/3.4.3.txt

[2]: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2019-12420

Marked as fixed in versions 3.4.3~rc6-1. Request was from Noah Meyerhans <noahm@debian.org> to control@bugs.debian.org. (Thu, 12 Dec 2019 21:21:10 GMT) (full text, mbox, link).


Marked as found in versions spamassassin/3.4.2-1~deb9u1. Request was from Noah Meyerhans <noahm@debian.org> to control@bugs.debian.org. (Thu, 12 Dec 2019 21:21:17 GMT) (full text, mbox, link).


Changed Bug title to 'spamassassin: CVE-2019-12420: specially crafted messages can exhaust system resources resulting in a denial of service' from 'spamassassin: specially crafted messages can exhaust system resources resulting in a denial of service'. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Thu, 12 Dec 2019 21:27:04 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Fri Dec 13 09:08:38 2019; Machine Name: beach

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.