{"schema_version":"1.7.3","id":"openSUSE-SU-2019:0297-1","published":"2019-03-23T11:10:44Z","modified":"2026-02-04T04:38:47.732605Z","related":["CVE-2016-1238"],"upstream":["CVE-2016-1238"],"summary":"Security update for amavisd-new","details":"This update for amavisd-new fixes the following issues:\n\nSecurity issue fixed: \n\n- CVE-2016-1238: Workedaround a perl vulnerability by removing a trailing dot element from @INC\t(bsc#987887).\n\nOther issues addressed:\n\n- update to version 2.11.1 (bsc#1123389).\n- amavis-services: bumping up syslog level from LOG_NOTICE to LOG_ERR\n  for a message 'PID <pid> went away', and removed redundant newlines\n  from some log messages\n- avoid warning messages 'Use of uninitialized value in subroutine entry' in Encode::MIME::Header\n  when the $check argument is undefined \n- @sa_userconf_maps has been extended to allow loading of per-recipient (or per-policy bank, or global) SpamAssassin configuration set from LDAP. \n  For consistency with SQL a @sa_userconf_maps entry prefixed with 'ldap:' will load SpamAssassin configuration set using the load_scoreonly_ldap() method.\n- add some Sanesecurity.Foxhole false positives to the default list @virus_name_to_spam_score_maps\n\n- update amavis-milter to version 2.6.1:\n  * Fixed a  bug when creating amavisd-new policy bank names\n\nThis update was imported from the SUSE:SLE-15:Update update project.","references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/T5ANAUXCDCGLYH4N2EPY5MA7CJJND4MP/#T5ANAUXCDCGLYH4N2EPY5MA7CJJND4MP"},{"type":"REPORT","url":"https://bugzilla.suse.com/1123389"},{"type":"REPORT","url":"https://bugzilla.suse.com/987887"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-1238"}]}