Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-9920

Опубликовано: 08 дек. 2016
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6
CVSS3: 7.5

Описание

steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail command line, which allows remote authenticated users to execute arbitrary code via a modified HTTP request that sends a crafted e-mail message.

РелизСтатусПримечание
artful

not-affected

1.2.3+dfsg.1-1
bionic

not-affected

1.3.6+dfsg.1-1
cosmic

not-affected

1.3.6+dfsg.1-1
devel

not-affected

1.3.6+dfsg.1-1
disco

not-affected

1.3.6+dfsg.1-1
eoan

not-affected

1.3.6+dfsg.1-1
esm-apps-legacy/xenial

released

1.2~beta+dfsg.1-0ubuntu1+esm7
esm-apps/bionic

not-affected

1.3.6+dfsg.1-1
esm-apps/focal

not-affected

1.3.6+dfsg.1-1
esm-apps/jammy

not-affected

1.3.6+dfsg.1-1

Показывать по

EPSS

Процентиль: 92%
0.056
Низкий

6 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 10 лет назад

steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail command line, which allows remote authenticated users to execute arbitrary code via a modified HTTP request that sends a crafted e-mail message.

CVSS3: 7.5
debian
почти 10 лет назад

steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2 ...

CVSS3: 7.5
github
больше 4 лет назад

steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail command line, which allows remote authenticated users to execute arbitrary code via a modified HTTP request that sends a crafted e-mail message.

EPSS

Процентиль: 92%
0.056
Низкий

6 Medium

CVSS2

7.5 High

CVSS3