CVE-2010-1132
Summary
| CVE | CVE-2010-1132 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-03-27 19:07:11 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacters in the RCPT TO field of an email message. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Georg Greve | Spamassassin Milter Plugin | 0.3.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 572117 – (CVE-2010-1132) CVE-2010-1132 SpamAssassin Mail Filter: Arbitrary shell command injection (privilege escalation) | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Apache Spamassassin Milter Plugin Remote Root Command Execution | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit |
| SpamAssassin Milter Plugin 'mlfi_envrcpt()' Remote Arbitrary Command Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| [SECURITY] Fedora 13 Update: spamass-milter-0.3.1-18.fc13 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| SpamAssassin Milter Plugin Shell Command Injection - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| #573228 - Arbitrary command execution (report from full-disclosure) - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | |
| NEOHAPSIS - Peace of Mind Through Integrity and Insight | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Exploit |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Debian update for spamass-milter - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Security Advisory SA39265 - Fedora update for spamass-milter - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Debian -- Security Information -- DSA-2021-1 spamass-milter | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| SecurityTracker.com Archives - SpamAssassin Milter Plugin Input Validation Flaw Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| osvdb.org/62809 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| [SECURITY] Fedora 12 Update: spamass-milter-0.3.1-18.fc12 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| [SECURITY] Fedora 11 Update: spamass-milter-0.3.1-18.fc11 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| SpamAssassin Milter Plugin - Bugs: bug #29136, SpamAssassin Milter Plugin Input... [Savannah] | af854a3a-2127-422b-91ae-364da2661108 | savannah.nongnu.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 690271 Free Berkeley Software Distribution (FreeBSD) Security Update for spamass-milter (7132c842-58e2-11df-8d80-0015587e2cc1)