SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2010-1132

The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacters in the RCPT TO field of an email message.

HIGH 9.3EPSS 8.58%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (8.58%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacters in the RCPT TO field of an email message.

CVSS 2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
8.58% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-78
Affected
georg greve/spamassassin milter plugin
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.