CVE-2018-11780
critical · 9.8A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.
9.8
CVSS
10.8%
EPSS (exploit prob.)
96th
EPSS percentile
2018-09-17
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-94
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | spamassassin | < 3.4.2 |
| pdfinfo_project | pdfinfo | all versions |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| debian | debian_linux | 8.0 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00002.html
- http://www.securityfocus.com/bid/105373
- https://lists.apache.org/thread.html/7f6a16bc0fd0fd5e67c7fd95bd655069a2ac7d1f88e42d3c853e601c%40%3Cannounce.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2018/11/msg00016.html
- https://security.gentoo.org/glsa/201812-07
- https://usn.ubuntu.com/3811-1/
- https://usn.ubuntu.com/3811-3/
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00002.html
- http://www.securityfocus.com/bid/105373
- https://lists.apache.org/thread.html/7f6a16bc0fd0fd5e67c7fd95bd655069a2ac7d1f88e42d3c853e601c%40%3Cannounce.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2018/11/msg00016.html
- https://security.gentoo.org/glsa/201812-07
- https://usn.ubuntu.com/3811-1/
- https://usn.ubuntu.com/3811-3/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-11780