A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.
https://usn.ubuntu.com/3811-3/
https://usn.ubuntu.com/3811-1/
https://security.gentoo.org/glsa/201812-07
https://lists.debian.org/debian-lts-announce/2018/11/msg00016.html
http://www.securityfocus.com/bid/105373
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00002.html