CVE-2017-15806
The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to execute arbitrary code via a crafted…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.7%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to execute arbitrary code via a crafted email address, as demonstrated by one containing "-X/path/to/wwwroot/file.php."
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 10.65% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- zetacomponents/mail
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/101866Third Party Advisory, VDB Entry
- https://github.com/zetacomponents/Mail/issues/58Issue Tracking, Third Party Advisory
- https://github.com/zetacomponents/Mail/releases/tag/1.8.2Issue Tracking, Release Notes, Third Party Advisory
- https://kay-malwarebenchmark.github.io/blog/cve-2017-15806-critical-rce-vulnerability/Issue Tracking, Third Party Advisory
- https://kay-malwarebenchmark.github.io/blog/cve-2017-15806-yuan-cheng-dai-ma-zhi-xing-lou-dong/Issue Tracking, Third Party Advisory
- https://www.exploit-db.com/exploits/43155/Issue Tracking, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/101866Third Party Advisory, VDB Entry
- https://github.com/zetacomponents/Mail/issues/58Issue Tracking, Third Party Advisory
- https://github.com/zetacomponents/Mail/releases/tag/1.8.2Issue Tracking, Release Notes, Third Party Advisory
- https://kay-malwarebenchmark.github.io/blog/cve-2017-15806-critical-rce-vulnerability/Issue Tracking, Third Party Advisory
- https://kay-malwarebenchmark.github.io/blog/cve-2017-15806-yuan-cheng-dai-ma-zhi-xing-lou-dong/Issue Tracking, Third Party Advisory
- https://www.exploit-db.com/exploits/43155/Issue Tracking, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.