imPC@ndo IT

Tracker / CVE-2019-12420

CVE-2019-12420

High 7.5

In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publicly.

Affected products and versions

apache spamassassin · … → 3.4.3
debian debian_linux

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References