CVE-2010-1132
The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacters in the RCPT TO field of an email message.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.58%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacters in the RCPT TO field of an email message.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 8.58% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- georg greve/spamassassin milter plugin
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2010-03/0139.htmlExploit
- http://bugs.debian.org/573228
- http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038535.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038572.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038777.html
- http://osvdb.org/62809
- http://secunia.com/advisories/38840Vendor Advisory
- http://secunia.com/advisories/38956Vendor Advisory
- http://secunia.com/advisories/39265Vendor Advisory
- http://www.debian.org/security/2010/dsa-2021
- http://www.exploit-db.com/exploits/11662Exploit
- http://www.securityfocus.com/bid/38578Exploit
- http://www.securitytracker.com/id?1023691
- http://www.vupen.com/english/advisories/2010/0559Vendor Advisory
- http://www.vupen.com/english/advisories/2010/0683Vendor Advisory
- http://www.vupen.com/english/advisories/2010/0837Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=572117
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56732
- https://savannah.nongnu.org/bugs/?29136
- http://archives.neohapsis.com/archives/fulldisclosure/2010-03/0139.htmlExploit
- http://bugs.debian.org/573228
- http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038535.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038572.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038777.html
- http://osvdb.org/62809
- http://secunia.com/advisories/38840Vendor Advisory
- http://secunia.com/advisories/38956Vendor Advisory
- http://secunia.com/advisories/39265Vendor Advisory
- http://www.debian.org/security/2010/dsa-2021
- http://www.exploit-db.com/exploits/11662Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.