Login
Newsletter
Werbung

Sicherheit: Mangelnde Eingabeprüfung in PHPMailer
Aktuelle Meldungen Distributionen
Name: Mangelnde Eingabeprüfung in PHPMailer
ID: DSA-3416-1
Distribution: Debian
Plattformen: Debian sid, Debian wheezy, Debian jessie
Datum: So, 13. Dezember 2015, 20:34
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8476
Applikationen: PHPMailer

Originalnachricht

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- -------------------------------------------------------------------------
Debian Security Advisory DSA-3416-1 security@debian.org
https://www.debian.org/security/ Luciano Bello
December 13, 2015 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : libphp-phpmailer
CVE ID : CVE-2015-8476
Debian Bug : 807265

Takeshi Terada discovered a vulnerability in PHPMailer, a PHP library for
email transfer, used by many CMSs. The library accepted email addresses
and SMTP commands containing line breaks, which can be abused by an
attacker to inject messages.

For the oldstable distribution (wheezy), this problem has been fixed in
version 5.1-1+deb6u11.

For the stable distribution (jessie), this problem has been fixed in
version 5.2.9+dfsg-2+deb8u1.

For the unstable distribution (sid), this problem has been fixed in
version 5.2.14+dfsg-1.

We recommend that you upgrade your libphp-phpmailer packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJWbcIxAAoJEG7C3vaP/jd0Pw8P/iJwLRDYqr0lFGj5IWA3Tles
J2FTVmPz72ewepQFxNYwSAZ9x8YRwzD94Chy7MYnU91EBHSV/sYxft9HXY70BkgX
TsVdnvhF8Oz9zHk1czJcHu+ExyAGGy+2siWRlgFU4ABMY4Hd06MiLaPi6ZAVkU1f
MNWznrd8CDdKZ3AjXEnJiQYD6ig4wT3WfkNWcEWEdKqKniqF5/vqLAbwFnNCMGsP
4fFiqcChqpOviwi8CrTlPuHuZPZPE1wGF7ns9hM4mONhWmiMMhYmQJJ5s8RNY/W0
aQL14p2WtQfm/8zozA3sNqv5EUYJ9+kQUN6jD/YhvFf/idSTvsNljt5DnduZW8de
9t4vCJvwdAkY9EEDl7nQkh1hrWJCjh/rlDigdcNG7UFkctLJUNu6YKaM4BBOIARY
72huJREK/V3VYcLx6hN1fFa9QkaQfiQrTZt7mjjBIqUmzXOJQvTemsAvfbdS2MRY
NYB7Dz6muX0oqf76XUyzrl2mUqQX7/c8s7Cpb2ajgR4nE59xOgJTz3AKU/OZ0G/H
j+fYVMcO1JfTro3LauttEBeZBgWlntQlU2hb021NSY7q0oaVndr3/RWlFtyCF1Fc
+DlqLM4gdW1eZQDzu9PA+Eb5RGn7DuRzTtzvtVxGuHPcW0Jji94Hu3559UAmwg7W
Mupf98RrV0FmvtHYNJdf
=UHhf
-----END PGP SIGNATURE-----
Pro-Linux
Traut euch!
Neue Nachrichten
Werbung