View Full Version : SpamAssassin SECURITY UPDATE
Korsakoff
08-21-2004, 10:44 AM
Hello,
SpamAssassin contain vulns:
SpamAssassin SpamAssassin 2.40
SpamAssassin SpamAssassin 2.41
SpamAssassin SpamAssassin 2.42
SpamAssassin SpamAssassin 2.43
SpamAssassin SpamAssassin 2.44
SpamAssassin SpamAssassin 2.50
SpamAssassin SpamAssassin 2.55
SpamAssassin SpamAssassin 2.60
SpamAssassin SpamAssassin 2.63
see http://www.securityfocus.com/bid/10957 for more information, you need to update to version 2.64.
Korsakoff
interfasys
08-21-2004, 06:01 PM
DA needs to update its package then...But by reading the scripts, it seems that the standard spamassassin.org package should do.
Also, on a freebsd server, it seems spam.sh is looking in the wrong folder:
WEBFILE=http://files.directadmin.com/services/9.0/Mail-SpamAssassin-${VERSION}.tar.gz
Shouldn't it be looking in the freebsd5.1 folder (even if there is only one source file for all platforms)? Or maybe it would be a good idea to have a general allplatforms folder for those scripts that can be installed anywhere?
When will the DA package be ready?
blacknight
09-19-2004, 02:09 PM
Originally posted by jep
When will the DA package be ready?
I can't see any reason why you would have to use it. The installer does exactly the same thing that you would do if you were to grab the tar.gz from the SA site and install it manually
interfasys
09-22-2004, 05:36 PM
SpamAssassin 3.0.0 was released on 2004-09-22!
http://spamassassin.apache.org/downloads.cgi?update=200409211830
blacknight
09-22-2004, 06:12 PM
The new release has a number of new features that will be attractive to people combatting spam.
NB: Read the upgrade + install files before upgrading it.
There are a number of significant changes that will affect Bayes and other elements
If you can install it via Cpan it might be easier, as it will resolve any dependencies
werwin01
09-29-2004, 08:09 AM
The version DirectAdmin uses is: SpamAssassin 2.64 (2004-01-11)
How would I go about updating to 3.0?
interfasys
09-29-2004, 08:23 AM
DANGER! DANGER! DANGER!
blacknight
09-29-2004, 08:28 AM
Originally posted by werwin01
The version DirectAdmin uses is: SpamAssassin 2.64 (2004-01-11)
How would I go about updating to 3.0?
Grab the tarball from the SA site and read carefully the INSTALL and UPGRADE docs, as there are a number of significant differences. If you are using Bayes you will need to upgrade the DB format before the upgrade. There are also a number of other Perl modules that it uses that are not installed by default with the 2.6* series.
werwin01
09-29-2004, 02:45 PM
Originally posted by interfasys
DANGER! DANGER! DANGER!
Yea, with all these changes, I'll wait for it to be updated internally in DA
PauGasol
10-12-2004, 08:53 AM
I hope DA upgrade to 3.x before use it.. any dates?
redeye
10-27-2004, 03:07 AM
any news on this?
fusionictnl
10-27-2004, 03:29 AM
http://www.directadmin.com/forum/showthread.php?s=&threadid=4995
Do it yourself :D
PauGasol
10-27-2004, 08:37 AM
Originally posted by fusionictnl
http://www.directadmin.com/forum/showthread.php?s=&threadid=4995
Do it yourself :D
Thanks, be your method will compatible when DA updated to new versions ?
vBulletin® v3.7.0, Copyright ©2000-2008, Jelsoft Enterprises Ltd.