PT-2015-2870 · Php+1 · Phpmailer+1

Takeshi Terada

·

Publicado

2015-12-13

·

Atualizado

2020-03-05

·

CVE-2015-8476

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions PHPMailer versions prior to 5.2.14
Description The issue allows attackers to inject arbitrary SMTP commands via CRLF sequences in an email address to the validateAddress function in class.phpmailer.php or an SMTP command to the sendCommand function in class.smtp.php. This can be exploited by injecting line breaks into valid email addresses, which are not handled correctly in some contexts.
Recommendations For versions prior to 5.2.14, update to version 5.2.14 or later to resolve the issue. As a temporary workaround, consider manually stripping line breaks from email addresses before passing them to PHPMailer.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-2512
BDU:2015-12236
CVE-2015-8476
DLA-363-1
DSA-3416-1
GHSA-738M-F33V-QC2R
MGASA-2015-0484

Produtos afetados

Alt Linux
Phpmailer