GHSA-r9mw-gwx9-v3h5
zend-mail remote code execution via Sendmail adapter
Quick fix
GHSA-r9mw-gwx9-v3h5 — zendframework/zend-mail: upgrade to the fixed version with the command below.
composer require zendframework/zend-mail:^2.4.11Details
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 2.4.11composer require zendframework/zend-mail:^2.4.112.5No fixed version published yet for zendframework/zend-mail (composer). Pin to a known-safe version or switch to an alternative.
2.6No fixed version published yet for zendframework/zend-mail (composer). Pin to a known-safe version or switch to an alternative.
2.7Fixed in: 2.7.2composer require zendframework/zend-mail:^2.7.2References
- https://nvd.nist.gov/vuln/detail/CVE-2016-10034[ADVISORY]
- https://framework.zend.com/security/advisory/ZF2016-04[WEB]
- https://github.com/zendframework/zend-mail[PACKAGE]
- https://legalhackers.com/advisories/ZendFramework-Exploit-ZendMail-Remote-Code-Exec-CVE-2016-10034-Vuln.html[WEB]
- https://security.gentoo.org/glsa/201804-10[WEB]
- https://www.exploit-db.com/exploits/40979[WEB]
- https://www.exploit-db.com/exploits/40986[WEB]
- https://www.exploit-db.com/exploits/42221[WEB]
- http://www.securityfocus.com/bid/95144[WEB]
- http://www.securitytracker.com/id/1037539[WEB]