Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
CVE-2018-11781
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2018-11781
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-11781.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-11781
Downstream
ALPINE-CVE-2018-11781
DEBIAN-CVE-2018-11781
DLA-1578-1
RHSA-2018:2916
SUSE-SU-2019:1961-1
SUSE-SU-2019:2011-1
UBUNTU-CVE-2018-11781
USN-3811-1
openSUSE-SU-2019:1831-1
Related
MGASA-2018-0425
SUSE-SU-2019:1961-1
SUSE-SU-2019:2011-1
openSUSE-SU-2019:1831-1
Published
2018-09-17T14:29:00Z
Modified
2025-08-09T19:01:26Z
Severity
7.8 (High)
CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Calculator
Summary
[none]
Details
Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.
References
https://access.redhat.com/errata/RHSA-2018:2916
https://lists.debian.org/debian-lts-announce/2018/11/msg00016.html
https://security.gentoo.org/glsa/201812-07
https://usn.ubuntu.com/3811-1/
https://usn.ubuntu.com/3811-3/
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00002.html
https://lists.apache.org/thread.html/7f6a16bc0fd0fd5e67c7fd95bd655069a2ac7d1f88e42d3c853e601c%40%3Cannounce.apache.org%3E
Affected packages
Git
/
github.com/apache/spamassassin
Affected ranges
Type
GIT
Repo
https://github.com/apache/spamassassin
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Fixed
41ec240365da2278f32fed178c4e34b287c70d0e
CVE-2018-11781 - OSV