CVE-2019-12420 in Apache and Debian Products
Published on December 12, 2019
In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publicly.
Products Associated with CVE-2019-12420
stack.watch emails you whenever new vulnerabilities are published in Apache Spamassassin or Debian Linux. Just hit a watch button to start following.
Affected Versions
Apache SpamAssassin Version Apache SpamAssassin prior to 3.4.3 is affected by CVE-2019-12420Exploit Probability
EPSS
13.68%
Percentile
94.17%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.