Argument injection vulnerability in Mail/sendmail.php in the Mail package 1.1.14, 1.2.0b2, and possibly other versions for PEAR allows remote attackers to read and write arbitrary files via a crafted $recipients parameter, and possibly other parameters, a different vulnerability than CVE-2009-4023.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade php-mail | Jul 30, 2024 | Nov 29, 2009 |
| Gentoo Linux | — | Upgrade app-admin/syslog-ng.Upgrade net-libs/libsoup.Upgrade net-misc/rsync.Upgrade dev-php/PEAR-Mail.Upgrade dev-vcs/gitolite.Upgrade dev-db/unixODBC.Upgrade net-analyzer/sflowtool.Upgrade app-misc/ca-certificates.Upgrade app-office/gnucash.Upgrade gnome-base/gdm.Upgrade net-misc/vino.Upgrade media-sound/lastfmplayer.Upgrade dev-util/qt-creator.Upgrade sys-fs/lvm2.Upgrade sys-cluster/resource-agents.Upgrade dev-libs/xmlsec.Upgrade net-libs/webkit-gtk.Upgrade sys-apps/shadow.Upgrade dev-util/oprofile.Upgrade x11-apps/xrdb.Upgrade media-libs/xine-lib.Upgrade media-libs/fmod.Upgrade dev-php/PEAR-PEAR.Upgrade games-sports/racer-bin.Upgrade net-misc/mrouted. | Oct 30, 2017 | Nov 29, 2009 |
| Suse | — | Upgrade php5-pear-mail | Feb 17, 2015 | Nov 29, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub