PT-2011-2600 · Ruby · Ruby Mail Gem

Published

2011-02-02

·

Updated

2017-10-24

·

CVE-2011-0739

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ruby Mail gem versions 2.2.14 and earlier
Description The issue allows remote attackers to execute arbitrary commands via shell metacharacters in an e-mail address. This is due to a problem in the deliver function in the sendmail delivery agent, specifically in the lib/mail/network/delivery methods/sendmail.rb file.
Recommendations For Ruby Mail gem versions 2.2.14 and earlier, consider disabling the deliver function in the sendmail delivery agent until a patch is available. Restrict access to the lib/mail/network/delivery methods/sendmail.rb file to minimize the risk of exploitation. Avoid using e-mail addresses with shell metacharacters in the affected delivery agent until the issue is resolved.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-0739
GHSA-CPJC-P7FC-J9XH

Affected Products

Ruby Mail Gem