PT-2016-4569 · Swift · Swiftmailer

Dawid Golunski

+1

·

Published

2016-12-30

·

Updated

2022-05-17

·

CVE-2016-10074

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Swift Mailer versions prior to 5.4.5
Description The issue allows remote attackers to potentially execute arbitrary code by passing extra parameters to the mail command. This can be achieved by including a (backslash double quote) in a crafted e-mail address within the From, ReturnPath, or Sender header.
Recommendations For versions prior to 5.4.5, update to version 5.4.5 or later to resolve the issue. As a temporary workaround, consider restricting the use of special characters in e-mail addresses within the From, ReturnPath, or Sender headers until a patch is applied.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-10074
DLA-792-1
DSA-3769-1
GHSA-PR44-4JFR-286M

Affected Products

Swiftmailer