Argument injection vulnerability in the sendmail implementation of the Mail::Send method (Mail/sendmail.php) in the Mail package 1.1.14 for PEAR allows remote attackers to read and write arbitrary files via a crafted $from parameter, a different vector than CVE-2009-4111.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade php-mail | Jul 30, 2024 | Nov 29, 2009 |
| Gentoo Linux | — | Upgrade dev-vcs/gitolite.Upgrade media-libs/xine-lib.Upgrade dev-db/unixODBC.Upgrade sys-fs/lvm2.Upgrade net-libs/libsoup.Upgrade net-misc/rsync.Upgrade media-libs/fmod.Upgrade net-libs/webkit-gtk.Upgrade sys-apps/shadow.Upgrade app-misc/ca-certificates.Upgrade net-analyzer/sflowtool.Upgrade dev-util/oprofile.Upgrade app-office/gnucash.Upgrade media-sound/lastfmplayer.Upgrade net-misc/mrouted.Upgrade dev-php/PEAR-PEAR.Upgrade sys-cluster/resource-agents.Upgrade games-sports/racer-bin.Upgrade dev-util/qt-creator.Upgrade app-admin/syslog-ng.Upgrade x11-apps/xrdb.Upgrade net-misc/vino.Upgrade dev-libs/xmlsec.Upgrade gnome-base/gdm.Upgrade dev-php/PEAR-Mail. | Oct 30, 2017 | Nov 29, 2009 |
| Suse | — | Upgrade php5-pear-mail | Feb 17, 2015 | Nov 29, 2009 |
| Ubuntu | — | Upgrade php-mail | Nov 19, 2024 | Nov 29, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub