FreeBSD : PHPmailer -- SMTP injection vulnerability (8a90dc87-89f9-11e5-a408-00248c0c745d)

high Nessus Plugin ID 87188

Synopsis

The remote FreeBSD host is missing a security-related update.

Description

PHPMailer changelog reports :

Fix vulnerability that allowed email addresses with line breaks (valid in RFC5322) to pass to SMTP, permitting message injection at the SMTP level. Mitigated in both the address validator and in the lower-level SMTP class. Thanks to Takeshi Terada.

Solution

Update the affected package.

See Also

https://github.com/PHPMailer/PHPMailer/blob/v5.2.14/changelog.md

http://www.nessus.org/u?c8fe4446

Plugin Details

Severity: High

ID: 87188

File Name: freebsd_pkg_8a90dc8789f911e5a40800248c0c745d.nasl

Version: 2.4

Type: local

Published: 12/4/2015

Updated: 1/6/2021

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:phpmailer, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 12/3/2015

Vulnerability Publication Date: 11/5/2015