In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publicly.
References
Information
Published : 2019-12-12 15:15
Updated : 2020-01-13 11:15
NVD link : CVE-2019-12420
Mitre link : CVE-2019-12420
JSON object : View
CWE
CWE-400
Uncontrolled Resource Consumption
Products Affected
debian
- debian_linux
apache
- spamassassin