FreeBSD : PHPmailer -- SMTP injection vulnerability (8a90dc87-89f9-11e5-a408-00248c0c745d)

High Nessus Plugin ID 87188


The remote FreeBSD host is missing a security-related update.


PHPMailer changelog reports :

Fix vulnerability that allowed email addresses with line breaks (valid in RFC5322) to pass to SMTP, permitting message injection at the SMTP level. Mitigated in both the address validator and in the lower-level SMTP class. Thanks to Takeshi Terada.


Update the affected package.

See Also

Plugin Details

Severity: High

ID: 87188

File Name: freebsd_pkg_8a90dc8789f911e5a40800248c0c745d.nasl

Version: $Revision: 2.1 $

Type: local

Published: 2015/12/04

Modified: 2015/12/04

Dependencies: 12634

Risk Information

Risk Factor: High

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:phpmailer, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 2015/12/03

Vulnerability Publication Date: 2015/11/05