DEBIAN-CVE-2020-36326
Dashboard / Vulnerabilities / DEBIAN-CVE-2020-36326
Summary:
Details: PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in safe contexts. As an unintended side effect, this fix eliminated the code that blocked addAttachment exploitation.
Affected packages
Package
Name: libphp-phpmailer
Purl: pkg:deb/debian/libphp-phpmailer?arch=source&distro=bookworm
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -6.2.0-2
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
