Описание
Net::SMTP in Ruby before 2.4.0 is vulnerable to SMTP command injection via CRLF sequences in a RCPT TO or MAIL FROM command, as demonstrated by CRLF sequences immediately before and after a DATA substring.
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [1.9.3.484-2ubuntu1.3]] |
precise/esm | DNE | |
trusty | released | 1.9.3.484-2ubuntu1.3 |
trusty/esm | DNE | trusty was released [1.9.3.484-2ubuntu1.3] |
upstream | needed | |
vivid/stable-phone-overlay | DNE | |
vivid/ubuntu-core | DNE | |
xenial | DNE | |
yakkety | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [2.0.0.484-1ubuntu2.4]] |
precise/esm | DNE | |
trusty | released | 2.0.0.484-1ubuntu2.4 |
trusty/esm | DNE | trusty was released [2.0.0.484-1ubuntu2.4] |
upstream | needed | |
vivid/stable-phone-overlay | DNE | |
vivid/ubuntu-core | DNE | |
xenial | DNE | |
yakkety | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | released | 2.3.3-1ubuntu1 |
esm-infra-legacy/trusty | DNE | |
esm-infra/xenial | released | 2.3.1-2~16.04.2 |
precise/esm | DNE | |
trusty | DNE | |
trusty/esm | DNE | |
upstream | needed | |
vivid/stable-phone-overlay | DNE | |
vivid/ubuntu-core | DNE | |
xenial | released | 2.3.1-2~16.04.2 |
Показывать по
EPSS
4.3 Medium
CVSS2
6.1 Medium
CVSS3
Связанные уязвимости
Net::SMTP in Ruby before 2.4.0 is vulnerable to SMTP command injection via CRLF sequences in a RCPT TO or MAIL FROM command, as demonstrated by CRLF sequences immediately before and after a DATA substring.
Net::SMTP in Ruby before 2.4.0 is vulnerable to SMTP command injection via CRLF sequences in a RCPT TO or MAIL FROM command, as demonstrated by CRLF sequences immediately before and after a DATA substring.
Net::SMTP in Ruby before 2.4.0 is vulnerable to SMTP command injection ...
Net::SMTP in Ruby before 2.4.0 is vulnerable to SMTP command injection via CRLF sequences in a RCPT TO or MAIL FROM command, as demonstrated by CRLF sequences immediately before and after a DATA substring.
EPSS
4.3 Medium
CVSS2
6.1 Medium
CVSS3