Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-738m-f33v-qc2r

Опубликовано: 05 мар. 2020
Источник: github
Github: Прошло ревью

Описание

SMTP Injection in PHPMailer

Impact

Attackers could inject arbitrary SMTP commands via by exploiting the fact that valid email addresses may contain line breaks, which are not handled correctly in some contexts.

Patches

Fixed in 5.2.14 in this commit.

Workarounds

Manually strip line breaks from email addresses before passing them to PHPMailer.

References

https://nvd.nist.gov/vuln/detail/CVE-2015-8476

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

phpmailer/phpmailer

composer
Затронутые версииВерсия исправления

>= 5.0.0, < 5.2.14

5.2.14

EPSS

Процентиль: 76%
0.00948
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
около 10 лет назад

Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in class.phpmailer.php or (2) SMTP command to the sendCommand function in class.smtp.php, a different vulnerability than CVE-2012-0796.

nvd
около 10 лет назад

Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in class.phpmailer.php or (2) SMTP command to the sendCommand function in class.smtp.php, a different vulnerability than CVE-2012-0796.

debian
около 10 лет назад

Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 all ...

fstec
около 10 лет назад

Уязвимости операционной системы Debian GNU/Linux, позволяющие нарушителю внедрить произвольные SMTP-команды

EPSS

Процентиль: 76%
0.00948
Низкий

Дефекты

CWE-20