CVE-2015-8476
Summary
| CVE | CVE-2015-8476 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-12-16 21:59:05 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in class.phpmailer.php or (2) SMTP command to the sendCommand function in class.smtp.php, a different vulnerability than CVE-2012-0796. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 6.0 | All | All | All |
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Application | Phpmailer Project | Phpmailer | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Add test for line breaks in addresses vulnerability · PHPMailer/PHPMailer@6687a96 · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| [SECURITY] Fedora 23 Update: php-PHPMailer-5.2.14-1.fc23 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Debian -- Security Information -- DSA-3416-1 libphp-phpmailer | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| oss-security - CVE Request: PHPMailer Message Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| [SECURITY] Fedora 22 Update: php-PHPMailer-5.2.14-1.fc22 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Release PHPMailer 5.2.14 · PHPMailer/PHPMailer · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Vendor Advisory |
| oss-security - Re: CVE Request: PHPMailer Message Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| PHPMailer 'class.phpmailer.php' Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.