Ho lokolloa ha SpamAssassin 3.4.5 sisteme ea ho sefa ea spam ka ho felisoa ha tlokotsi.

Ho lokolloa ha sethala sa ho hloekisa spam ho fumaneha - SpamAssassin 3.4.5. SpamAssassin e sebelisa mokhoa o kopanetsoeng oa ho etsa qeto ea ho thibela: molaetsa o tlas'a licheke tse ngata (tlhahlobo ea maemo, manane a DNSBL a matšo le a masoeu, lihlopha tse koetlisitsoeng tsa Bayesian, ho hlahloba li-signature, netefatso ea motho ea romelang ho sebelisa SPF le DKIM, joalo-joalo). Ka mor'a ho hlahloba molaetsa ka mekhoa e fapaneng, ho bokelloa boima bo itseng ba boima. Haeba coefficient e baloang e feta moeli o itseng, molaetsa oa thibeloa kapa oa tšoauoa joalo ka spam. Lisebelisoa tsa ho ntlafatsa melao ea ho sefa ka bo eona lia tšehetsoa. Sephutheloana se ka sebelisoa ho litsamaiso tsa bareki le tsa seva. Khoutu ea SpamAssassin e ngotsoe Perl mme e ajoa tlasa laesense ea Apache.

Phatlalatso e ncha e lokisa ts'oaetso (CVE-2020-1946) e lumellang mohlaseli ho phethahatsa litaelo tsa tsamaiso ho seva ha a kenya melao e thibelang e sa netefatsoang e fumanoang mehloling ea batho ba bang.

Har'a liphetoho tse sa amaneng le ts'ireletso ke lintlafatso mosebetsing oa li-plugins tsa OLEVBMacro le AskDNS, ntlafatso ea ts'ebetso ea ho tsamaisana le data ho Received and EnvelopeFrom headers, tokiso ho userpref SQL schema, khoutu e ntlafalitsoeng ea licheke ho rbl le hashbl, le tharollo ea bothata ka li-tag tsa TxRep.

Hoa hlokomeloa hore nts'etsopele ea letoto la 3.4.x e khaotsoe 'me liphetoho ha li sa tla beoa lekaleng lena. Mokhelo o etsoa feela bakeng sa li-patches tsa bofokoli, haeba ho tla hlahisoa tokollo ea 3.4.6. Ts'ebetso eohle ea nts'etsopele e shebane le nts'etsopele ea lekala la 4.0, le tla kenya tšebetsong ts'ebetso e felletseng ea UTF-8.

Source: opennet.ru

Eketsa ka tlhaloso