spamassassin (3.4.2-1ubuntu0.19.04.1) disco-security; urgency=medium

  * SECURITY UPDATE: code execution via nefarious CF files
    - debian/patches/CVE-2018-11805: improve rule parsing.
    - CVE-2018-11805
  * SECURITY UPDATE: resource consumption issue
    - debian/patches/CVE-2019-12420: limit checked mime parts.
    - CVE-2019-12420
  * Thanks to Debian for the patches.

 -- Marc Deslauriers <email address hidden>  Fri, 10 Jan 2020 11:52:09 -0500

Marc Deslauriers on 2020-01-10
Ubuntu Developers
Medium Urgency

Disco updates on 2020-01-13 main mail
Disco security on 2020-01-13 main mail


File Size SHA-256 Checksum
spamassassin_3.4.2.orig-pkgrules.tar.xz 228.7 KiB 3f3349bb45ac63a7b85a7562a365a9805c4afce91aa11718f0dacfe034890066
spamassassin_3.4.2.orig.tar.xz 1.8 MiB aae73f835e1201713458fbe012f686eae395f7672c4729e62c91a92b3ced50df
spamassassin_3.4.2-1ubuntu0.19.04.1.debian.tar.xz 59.1 KiB 13ddd96f5fa2385235677ae0ce2efd9e6dfb2ff761441154344cf9362309e5de
spamassassin_3.4.2-1ubuntu0.19.04.1.dsc 2.5 KiB 1ae28ddf292f377bdc8f64f635461f0c958570fd6c56516cbff8ab0dba534b35

sa-compile: Tools for compiling SpamAssassin rules into C

 sa-compile uses "re2c" to compile the site-wide parts of the
 SpamAssassin ruleset into C code for more efficient processing by
 spamd or spamassassin.

spamassassin: Perl-based spam filter using text analysis

 SpamAssassin is a very powerful and fully configurable spam filter
 with numerous features including automatic white-listing, RBL
 testing, Bayesian analysis, header and body text analysis. It is
 designed to be called from a user's .procmail or .forward file, but
 can also be integrated into a Mail Transport Agent (MTA).
 Included in this package is a daemonized form of spamassassin (spamd)
 which communicates with its client (spamc) via TCP, to reduce the
 overhead of loading perl with each message. To take advantage of
 this, you must install the spamc package.

spamc: Client for SpamAssassin spam filtering daemon

 spamc is the client to communicate with spamd, the daemonized form of
 SpamAssassin (see the spamassassin package). It is written in C for
 maximum speed and minimum loading overhead.
 spamc is quite useful for integrating spamassassin into an MTA or
 into a .procmailrc file because of its speed.
 This package is useless unless you have spamassassin installed,
 either on this machine or another local machine (i.e. a mail server).

spamc-dbgsym: debug symbols for spamc