{"api_version":"1","generated_at":"2026-07-23T08:18:11+00:00","cve":"CVE-2010-1132","urls":{"html":"https://cve.report/CVE-2010-1132","api":"https://cve.report/api/cve/CVE-2010-1132.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-1132","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-1132"},"summary":{"title":"CVE-2010-1132","description":"The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacters in the RCPT TO field of an email message.","state":"PUBLISHED","assigner":"mitre","published_at":"2010-03-27 19:07:11","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-78","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=572117","name":"https://bugzilla.redhat.com/show_bug.cgi?id=572117","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"572117 – (CVE-2010-1132) CVE-2010-1132 SpamAssassin Mail Filter: Arbitrary shell command injection (privilege escalation)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.exploit-db.com/exploits/11662","name":"http://www.exploit-db.com/exploits/11662","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Apache Spamassassin Milter Plugin Remote Root Command Execution","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/38578","name":"http://www.securityfocus.com/bid/38578","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"SpamAssassin Milter Plugin 'mlfi_envrcpt()' Remote Arbitrary Command Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038777.html","name":"http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038777.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[SECURITY] Fedora 13 Update: spamass-milter-0.3.1-18.fc13","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/38840","name":"http://secunia.com/advisories/38840","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SpamAssassin Milter Plugin Shell Command Injection - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://bugs.debian.org/573228","name":"http://bugs.debian.org/573228","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"#573228 - Arbitrary command execution (report from full-disclosure) - Debian Bug report logs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/fulldisclosure/2010-03/0139.html","name":"http://archives.neohapsis.com/archives/fulldisclosure/2010-03/0139.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"NEOHAPSIS - Peace of Mind Through Integrity and Insight","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2010/0837","name":"http://www.vupen.com/english/advisories/2010/0837","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/38956","name":"http://secunia.com/advisories/38956","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Debian update for spamass-milter - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2010/0683","name":"http://www.vupen.com/english/advisories/2010/0683","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/39265","name":"http://secunia.com/advisories/39265","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Advisory SA39265 - Fedora update for spamass-milter - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2010/dsa-2021","name":"http://www.debian.org/security/2010/dsa-2021","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-2021-1 spamass-milter","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1023691","name":"http://www.securitytracker.com/id?1023691","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - SpamAssassin Milter Plugin Input Validation Flaw Lets Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/62809","name":"http://osvdb.org/62809","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/56732","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/56732","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038535.html","name":"http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038535.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[SECURITY] Fedora 12 Update: spamass-milter-0.3.1-18.fc12","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2010/0559","name":"http://www.vupen.com/english/advisories/2010/0559","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038572.html","name":"http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038572.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[SECURITY] Fedora 11 Update: spamass-milter-0.3.1-18.fc11","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://savannah.nongnu.org/bugs/?29136","name":"https://savannah.nongnu.org/bugs/?29136","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SpamAssassin Milter Plugin - Bugs: bug #29136, SpamAssassin Milter Plugin Input... [Savannah]","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-1132","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-1132","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"1132","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"georg_greve","cpe5":"spamassassin_milter_plugin","cpe6":"0.3.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2010-1132","qid":"690271","title":"Free Berkeley Software Distribution (FreeBSD) Security Update for spamass-milter (7132c842-58e2-11df-8d80-0015587e2cc1)"}]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T01:14:06.296Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2010-0559","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/0559"},{"name":"20100307 Spamassassin Milter Plugin Remote Root","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://archives.neohapsis.com/archives/fulldisclosure/2010-03/0139.html"},{"name":"ADV-2010-0683","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/0683"},{"name":"39265","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39265"},{"name":"ADV-2010-0837","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/0837"},{"name":"38578","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/38578"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=572117"},{"name":"DSA-2021","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2010/dsa-2021"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://savannah.nongnu.org/bugs/?29136"},{"name":"11662","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"http://www.exploit-db.com/exploits/11662"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://bugs.debian.org/573228"},{"name":"FEDORA-2010-5096","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038535.html"},{"name":"1023691","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023691"},{"name":"62809","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/62809"},{"name":"spamassassin-expand-command-execution(56732)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/56732"},{"name":"38956","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38956"},{"name":"38840","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38840"},{"name":"FEDORA-2010-5112","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038777.html"},{"name":"FEDORA-2010-5176","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038572.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-03-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacters in the RCPT TO field of an email message."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2010-0559","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/0559"},{"name":"20100307 Spamassassin Milter Plugin Remote Root","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://archives.neohapsis.com/archives/fulldisclosure/2010-03/0139.html"},{"name":"ADV-2010-0683","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/0683"},{"name":"39265","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39265"},{"name":"ADV-2010-0837","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/0837"},{"name":"38578","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/38578"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=572117"},{"name":"DSA-2021","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2010/dsa-2021"},{"tags":["x_refsource_CONFIRM"],"url":"https://savannah.nongnu.org/bugs/?29136"},{"name":"11662","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"http://www.exploit-db.com/exploits/11662"},{"tags":["x_refsource_CONFIRM"],"url":"http://bugs.debian.org/573228"},{"name":"FEDORA-2010-5096","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038535.html"},{"name":"1023691","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023691"},{"name":"62809","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/62809"},{"name":"spamassassin-expand-command-execution(56732)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/56732"},{"name":"38956","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38956"},{"name":"38840","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38840"},{"name":"FEDORA-2010-5112","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038777.html"},{"name":"FEDORA-2010-5176","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038572.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2010-1132","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacters in the RCPT TO field of an email message."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2010-0559","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2010/0559"},{"name":"20100307 Spamassassin Milter Plugin Remote Root","refsource":"FULLDISC","url":"http://archives.neohapsis.com/archives/fulldisclosure/2010-03/0139.html"},{"name":"ADV-2010-0683","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2010/0683"},{"name":"39265","refsource":"SECUNIA","url":"http://secunia.com/advisories/39265"},{"name":"ADV-2010-0837","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2010/0837"},{"name":"38578","refsource":"BID","url":"http://www.securityfocus.com/bid/38578"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=572117","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=572117"},{"name":"DSA-2021","refsource":"DEBIAN","url":"http://www.debian.org/security/2010/dsa-2021"},{"name":"https://savannah.nongnu.org/bugs/?29136","refsource":"CONFIRM","url":"https://savannah.nongnu.org/bugs/?29136"},{"name":"11662","refsource":"EXPLOIT-DB","url":"http://www.exploit-db.com/exploits/11662"},{"name":"http://bugs.debian.org/573228","refsource":"CONFIRM","url":"http://bugs.debian.org/573228"},{"name":"FEDORA-2010-5096","refsource":"FEDORA","url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038535.html"},{"name":"1023691","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1023691"},{"name":"62809","refsource":"OSVDB","url":"http://osvdb.org/62809"},{"name":"spamassassin-expand-command-execution(56732)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/56732"},{"name":"38956","refsource":"SECUNIA","url":"http://secunia.com/advisories/38956"},{"name":"38840","refsource":"SECUNIA","url":"http://secunia.com/advisories/38840"},{"name":"FEDORA-2010-5112","refsource":"FEDORA","url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038777.html"},{"name":"FEDORA-2010-5176","refsource":"FEDORA","url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038572.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2010-1132","datePublished":"2010-03-26T21:00:00.000Z","dateReserved":"2010-03-26T00:00:00.000Z","dateUpdated":"2024-08-07T01:14:06.296Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-03-27 19:07:11","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-78","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:georg_greve:spamassassin_milter_plugin:0.3.1:*:*:*:*:*:*:*","matchCriteriaId":"D0D89A07-9688-4677-BF33-C11A86435355"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"1132","Ordinal":"1","Title":"CVE-2010-1132","CVE":"CVE-2010-1132","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"1132","Ordinal":"1","NoteData":"The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacters in the RCPT TO field of an email message.","Type":"Description","Title":"CVE-2010-1132"},{"CveYear":"2010","CveId":"1132","Ordinal":"2","NoteData":"2010-03-26","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"1132","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}