PT-2011-2600 · Ruby · Ruby Mail Gem
Published
2011-02-02
·
Updated
2017-10-24
·
CVE-2011-0739
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Ruby Mail gem versions 2.2.14 and earlier
Description
The issue allows remote attackers to execute arbitrary commands via shell metacharacters in an e-mail address. This is due to a problem in the deliver function in the sendmail delivery agent, specifically in the
lib/mail/network/delivery methods/sendmail.rb file.Recommendations
For Ruby Mail gem versions 2.2.14 and earlier, consider disabling the deliver function in the sendmail delivery agent until a patch is available. Restrict access to the
lib/mail/network/delivery methods/sendmail.rb file to minimize the risk of exploitation. Avoid using e-mail addresses with shell metacharacters in the affected delivery agent until the issue is resolved.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ruby Mail Gem