[Bug 669257] New: VUL-0: ruby mail gem shell command injection
https://bugzilla.novell.com/show_bug.cgi?id=669257 https://bugzilla.novell.com/show_bug.cgi?id=669257#c0 Summary: VUL-0: ruby mail gem shell command injection Classification: openSUSE Product: openSUSE 11.3 Version: Final Platform: Other OS/Version: Other Status: NEW Severity: Normal Priority: P5 - None Component: Other AssignedTo: mrueckert@novell.com ReportedBy: thomas@novell.com QAContact: qa@suse.de CC: security-team@suse.de Found By: --- Blocker: --- Hi, do we have this gem? CVE-ID: CVE-2011-0739 URL: The deliver function in the sendmail delivery agent (lib/mail/network/delivery_methods/sendmail.rb) in Ruby Mail gem 2.2.14 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an e-mail address. Reference: MISC: https://github.com/mikel/mail/raw/master/patches/20110126_sendmail.patch Reference: XF: http://xforce.iss.net/xforce/xfdb/65010 Reference: VUPEN: http://www.vupen.com/english/advisories/2011/0233 Reference: BID: http://www.securityfocus.com/bid/46021 Reference: SECUNIA: http://secunia.com/advisories/43077 Reference: OSVDB: http://osvdb.org/70667 Reference: CONFIRM: http://groups.google.com/group/mail-ruby/browse_thread/thread/e93bbd05706478... Reference: FEDORA: http://lists.fedoraproject.org/pipermail/package-announce/2011-January/05346... Reference: MISC: http://grid.ncsa.illinois.edu/myproxy/security/myproxy-adv-2011-01.txt -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=669257 https://bugzilla.novell.com/show_bug.cgi?id=669257#c1 Marcus Rückert <mrueckert@novell.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED Resolution| |FIXED --- Comment #1 from Marcus Rückert <mrueckert@novell.com> 2011-02-03 18:01:22 UTC --- afaik only in the obs and there i update the package already. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com