PEAR Sendmail 'Recipient' Parameter Arbitrary Argument Injection Vulnerability
BID:37395
Info
PEAR Sendmail 'Recipient' Parameter Arbitrary Argument Injection Vulnerability
| Bugtraq ID: | 37395 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4111 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 28 2009 12:00AM |
| Updated: | Dec 19 2014 12:56AM |
| Credit: | Josh Bressers |
| Vulnerable: |
SuSE SUSE Linux Enterprise 11 SP1 SuSE SUSE Linux Enterprise 11 PEAR PEAR 1.1.14 Gentoo Linux |
| Not Vulnerable: |
PEAR PEAR 1.2.0b2 |
Discussion
PEAR Sendmail 'Recipient' Parameter Arbitrary Argument Injection Vulnerability
PEAR is prone to a remote argument-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Remote attackers can exploit this issue to pass arbitrary arguments to the 'sendmail' command. This may allow attackers to obtain the contents of arbitrary files, overwrite arbitrary files, or launch other attacks.
The issue affects PEAR 1.1.14; other versions may also be affected.
PEAR is prone to a remote argument-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Remote attackers can exploit this issue to pass arbitrary arguments to the 'sendmail' command. This may allow attackers to obtain the contents of arbitrary files, overwrite arbitrary files, or launch other attacks.
The issue affects PEAR 1.1.14; other versions may also be affected.
Exploit / POC
PEAR Sendmail 'Recipient' Parameter Arbitrary Argument Injection Vulnerability
An attacker can exploit the issue via a browser.
An attacker can exploit the issue via a browser.
Solution / Fix
PEAR Sendmail 'Recipient' Parameter Arbitrary Argument Injection Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
PEAR Sendmail 'Recipient' Parameter Arbitrary Argument Injection Vulnerability
References:
References: