PEAR Sendmail 'From' Parameter Arbitrary Argument Injection Vulnerability
BID:37081
Info
PEAR Sendmail 'From' Parameter Arbitrary Argument Injection Vulnerability
| Bugtraq ID: | 37081 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4023 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 20 2009 12:00AM |
| Updated: | Apr 13 2015 09:29PM |
| Credit: | websec |
| Vulnerable: |
SuSE SUSE Linux Enterprise 11 SP1 SuSE SUSE Linux Enterprise 11 PEAR PEAR 1.1.14 Mandriva Linux Mandrake 2010.0 x86_64 Mandriva Linux Mandrake 2010.0 Mandriva Linux Mandrake 2009.1 x86_64 Mandriva Linux Mandrake 2009.1 Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Gentoo Linux Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 armel Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
PEAR PEAR 1.2.0b2 |
Discussion
PEAR Sendmail 'From' Parameter Arbitrary Argument Injection Vulnerability
PEAR is prone to a remote argument-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Remote attackers can exploit this issue to pass arbitrary arguments to the 'sendmail' command. This may allow attackers to obtain the contents of arbitrary files or launch other attacks.
The issue affects PEAR 1.1.14; other versions may also be affected.
PEAR is prone to a remote argument-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Remote attackers can exploit this issue to pass arbitrary arguments to the 'sendmail' command. This may allow attackers to obtain the contents of arbitrary files or launch other attacks.
The issue affects PEAR 1.1.14; other versions may also be affected.
Exploit / POC
PEAR Sendmail 'From' Parameter Arbitrary Argument Injection Vulnerability
An attacker can exploit the issue via a browser.
An attacker can exploit the issue via a browser.
Solution / Fix
PEAR Sendmail 'From' Parameter Arbitrary Argument Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Debian Linux 4.0 arm
Debian Linux 5.0 ia-64
Mandriva Linux Mandrake 2009.1 x86_64
Debian Linux 4.0 powerpc
MandrakeSoft Enterprise Server 5 x86_64
Debian Linux 4.0 m68k
Debian Linux 5.0 alpha
Debian Linux 5.0 ia-32
Mandriva Linux Mandrake 2008.0 x86_64
MandrakeSoft Enterprise Server 5
Debian Linux 5.0 s/390
Mandriva Linux Mandrake 2008.0
Debian Linux 5.0 mipsel
Mandriva Linux Mandrake 2010.0
Debian Linux 4.0 amd64
Mandriva Linux Mandrake 2010.0 x86_64
Debian Linux 4.0 ia-32
Debian Linux 5.0 hppa
Debian Linux 4.0 hppa
Debian Linux 4.0 sparc
Debian Linux 4.0 s/390
Debian Linux 5.0 m68k
Mandriva Linux Mandrake 2009.0
Debian Linux 5.0 arm
Debian Linux 4.0 alpha
Debian Linux 4.0 armel
Debian Linux 5.0 armel
MandrakeSoft Corporate Server 4.0
Debian Linux 5.0
Debian Linux 4.0
Debian Linux 4.0 mipsel
Mandriva Linux Mandrake 2009.0 x86_64
Debian Linux 5.0 amd64
Debian Linux 5.0 mips
Mandriva Linux Mandrake 2009.1
Debian Linux 5.0 powerpc
Debian Linux 4.0 ia-64
Debian Linux 4.0 mips
Debian Linux 5.0 sparc
MandrakeSoft Corporate Server 4.0 x86_64
Solution:
Updates are available. Please see the references for more information.
Debian Linux 4.0 arm
-
Debian php-mail_1.1.6-2+etch1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.6 -2+etch1_all.deb
Debian Linux 5.0 ia-64
-
Debian php-mail_1.1.14-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.1 4-1+lenny1_all.deb
Mandriva Linux Mandrake 2009.1 x86_64
-
Mandriva php-pear-5.2.9-1.1mdv2009.1.noarch.rpm
http://www.mandriva.com/en/download/
Debian Linux 4.0 powerpc
-
Debian php-mail_1.1.6-2+etch1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.6 -2+etch1_all.deb
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva php-pear-5.2.6-6.1mdvmes5.noarch.rpm
http://www.mandriva.com/en/download/
Debian Linux 4.0 m68k
-
Debian php-mail_1.1.6-2+etch1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.6 -2+etch1_all.deb
Debian Linux 5.0 alpha
-
Debian php-mail_1.1.14-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.1 4-1+lenny1_all.deb
Debian Linux 5.0 ia-32
-
Debian php-mail_1.1.14-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.1 4-1+lenny1_all.deb
Mandriva Linux Mandrake 2008.0 x86_64
-
Mandriva php-pear-5.2.4-1.1mdv2008.0.noarch.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Enterprise Server 5
-
Mandriva php-pear-5.2.6-6.1mdvmes5.noarch.rpm
http://www.mandriva.com/en/download/
Debian Linux 5.0 s/390
-
Debian php-mail_1.1.14-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.1 4-1+lenny1_all.deb
Mandriva Linux Mandrake 2008.0
-
Mandriva php-pear-5.2.4-1.1mdv2008.0.noarch.rpm
http://www.mandriva.com/en/download/
Debian Linux 5.0 mipsel
-
Debian php-mail_1.1.14-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.1 4-1+lenny1_all.deb
Mandriva Linux Mandrake 2010.0
-
Mandriva php-pear-Mail-1.2.0-0.b1.2.1mdv2010.0.noarch.rpm
http://www.mandriva.com/en/download/
Debian Linux 4.0 amd64
-
Debian php-mail_1.1.6-2+etch1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.6 -2+etch1_all.deb
Mandriva Linux Mandrake 2010.0 x86_64
-
Mandriva php-pear-Mail-1.2.0-0.b1.2.1mdv2010.0.noarch.rpm
http://www.mandriva.com/en/download/
Debian Linux 4.0 ia-32
-
Debian php-mail_1.1.6-2+etch1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.6 -2+etch1_all.deb
Debian Linux 5.0 hppa
-
Debian php-mail_1.1.14-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.1 4-1+lenny1_all.deb
Debian Linux 4.0 hppa
-
Debian php-mail_1.1.6-2+etch1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.6 -2+etch1_all.deb
Debian Linux 4.0 sparc
-
Debian php-mail_1.1.6-2+etch1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.6 -2+etch1_all.deb
Debian Linux 4.0 s/390
-
Debian php-mail_1.1.6-2+etch1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.6 -2+etch1_all.deb
Debian Linux 5.0 m68k
-
Debian php-mail_1.1.14-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.1 4-1+lenny1_all.deb
Mandriva Linux Mandrake 2009.0
-
Mandriva php-pear-5.2.6-6.1mdv2009.0.noarch.rpm
http://www.mandriva.com/en/download/
Debian Linux 5.0 arm
-
Debian php-mail_1.1.14-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.1 4-1+lenny1_all.deb
Debian Linux 4.0 alpha
-
Debian php-mail_1.1.6-2+etch1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.6 -2+etch1_all.deb
Debian Linux 4.0 armel
-
Debian php-mail_1.1.6-2+etch1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.6 -2+etch1_all.deb
Debian Linux 5.0 armel
-
Debian php-mail_1.1.14-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.1 4-1+lenny1_all.deb
MandrakeSoft Corporate Server 4.0
-
Mandriva php-pear-5.1.4-3.2.20060mlcs4.noarch.rpm
http://www.mandriva.com/en/download/
Debian Linux 5.0
-
Debian php-mail_1.1.14-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.1 4-1+lenny1_all.deb
Debian Linux 4.0
-
Debian php-mail_1.1.6-2+etch1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.6 -2+etch1_all.deb
Debian Linux 4.0 mipsel
-
Debian php-mail_1.1.6-2+etch1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.6 -2+etch1_all.deb
Mandriva Linux Mandrake 2009.0 x86_64
-
Mandriva php-pear-5.2.6-6.1mdv2009.0.noarch.rpm
http://www.mandriva.com/en/download/
Debian Linux 5.0 amd64
-
Debian php-mail_1.1.14-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.1 4-1+lenny1_all.deb
Debian Linux 5.0 mips
-
Debian php-mail_1.1.14-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.1 4-1+lenny1_all.deb
Mandriva Linux Mandrake 2009.1
-
Mandriva php-pear-5.2.9-1.1mdv2009.1.noarch.rpm
http://www.mandriva.com/en/download/
Debian Linux 5.0 powerpc
-
Debian php-mail_1.1.14-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.1 4-1+lenny1_all.deb
Debian Linux 4.0 ia-64
-
Debian php-mail_1.1.6-2+etch1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.6 -2+etch1_all.deb
Debian Linux 4.0 mips
-
Debian php-mail_1.1.6-2+etch1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.6 -2+etch1_all.deb
Debian Linux 5.0 sparc
-
Debian php-mail_1.1.14-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/p/php-mail/php-mail_1.1.1 4-1+lenny1_all.deb
MandrakeSoft Corporate Server 4.0 x86_64
-
Mandriva php-pear-5.1.4-3.2.20060mlcs4.noarch.rpm
http://www.mandriva.com/en/download/
References
PEAR Sendmail 'From' Parameter Arbitrary Argument Injection Vulnerability
References:
References: