Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23032
HistoryApr 10, 2020 - 12:13 a.m.

Remote Code Execution (RCE)

2020-04-1000:13:09
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.947 High

EPSS

Percentile

99.3%

SpamAssassin is vulnerable to Remote Code Execution (RCE). A flaw was found with the way the Spamassassin spamd daemon processes the virtual pop username passed to it. If a site is running spamd with both the --vpopmail and --paranoid flags, it is possible for a remote user with the ability to connect to the spamd daemon to execute arbitrary commands as the user running the spamd daemon.

References