PT-2017-7544 · Ruby+3 · Ruby+3

Jeremy

·

Publicado

2017-06-12

·

Atualizado

2020-06-09

·

CVE-2015-9096

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ruby versions prior to 2.4.0
Description The issue allows attackers to inject SMTP commands using CRLF sequences in RCPT TO or MAIL FROM commands. This can be demonstrated by CRLF sequences immediately before and after a DATA substring.
Recommendations For versions prior to 2.4.0, update to version 2.4.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of CRLF sequences in RCPT TO or MAIL FROM commands to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2195
CVE-2015-9096
DLA-1421-1
DSA-3966-1
MGASA-2017-0290
RHSA-2026:7305
RHSA-2026:7307
RHSA-2026:8838
SUSE-SU-2020:1570-1
SUSE-SU-2020_1570-1
USN-3365-1

Produtos afetados

Alt Linux
Ruby
Suse
Ubuntu