Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-9920

Опубликовано: 08 дек. 2016
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 6
CVSS3: 7.5

Описание

steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail command line, which allows remote authenticated users to execute arbitrary code via a modified HTTP request that sends a crafted e-mail message.

РелизСтатусПримечание
artful

not-affected

1.2.3+dfsg.1-1
bionic

not-affected

1.3.6+dfsg.1-1
cosmic

not-affected

1.3.6+dfsg.1-1
devel

not-affected

1.3.6+dfsg.1-1
disco

not-affected

1.3.6+dfsg.1-1
eoan

not-affected

1.3.6+dfsg.1-1
esm-apps/bionic

not-affected

1.3.6+dfsg.1-1
esm-apps/focal

not-affected

1.3.6+dfsg.1-1
esm-apps/jammy

not-affected

1.3.6+dfsg.1-1
esm-apps/noble

not-affected

1.3.6+dfsg.1-1

Показывать по

EPSS

Процентиль: 97%
0.44834
Средний

6 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 9 лет назад

steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail command line, which allows remote authenticated users to execute arbitrary code via a modified HTTP request that sends a crafted e-mail message.

CVSS3: 7.5
debian
около 9 лет назад

steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2 ...

CVSS3: 7.5
github
больше 3 лет назад

steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail command line, which allows remote authenticated users to execute arbitrary code via a modified HTTP request that sends a crafted e-mail message.

EPSS

Процентиль: 97%
0.44834
Средний

6 Medium

CVSS2

7.5 High

CVSS3