CVE-2015-8476
Summary
| CVE | CVE-2015-8476 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-12-16 21:59:00 UTC |
| Updated | 2016-12-06 03:03:00 UTC |
| Description | Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in class.phpmailer.php or (2) SMTP command to the sendCommand function in class.smtp.php, a different vulnerability than CVE-2012-0796. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 6.0 | All | All | All |
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 6.0 | All | All | All |
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Application | Phpmailer Project | Phpmailer | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Add test for line breaks in addresses vulnerability · PHPMailer/PHPMailer@6687a96 · GitHub | CONFIRM | github.com | |
| Release PHPMailer 5.2.14 · PHPMailer/PHPMailer · GitHub | CONFIRM | github.com | Vendor Advisory |
| oss-security - CVE Request: PHPMailer Message Injection Vulnerability | MLIST | www.openwall.com | |
| oss-security - Re: CVE Request: PHPMailer Message Injection Vulnerability | MLIST | www.openwall.com | |
| [SECURITY] Fedora 23 Update: php-PHPMailer-5.2.14-1.fc23 | FEDORA | lists.fedoraproject.org | |
| PHPMailer 'class.phpmailer.php' Security Bypass Vulnerability | BID | www.securityfocus.com | |
| Debian -- Security Information -- DSA-3416-1 libphp-phpmailer | DEBIAN | www.debian.org | |
| [SECURITY] Fedora 22 Update: php-PHPMailer-5.2.14-1.fc22 | FEDORA | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.