In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publicly. Reference: https://lists.apache.org/thread.html/5863d6c42fc9595a29566732f12348cde0ca0e41bda91695c62041de@%3Cannounce.apache.org%3E
Created spamassassin tracking bugs for this issue: Affects: fedora-all [bug 1784986]
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:3973 https://access.redhat.com/errata/RHSA-2020:3973
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-12420
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:4625 https://access.redhat.com/errata/RHSA-2020:4625