GHSA-738m-f33v-qc2r
Dashboard / Vulnerabilities / GHSA-738m-f33v-qc2r
Summary: SMTP Injection in PHPMailer
Details: ### Impact Attackers could inject arbitrary SMTP commands via by exploiting the fact that valid email addresses may contain line breaks, which are not handled correctly in some contexts. ### Patches Fixed in 5.2.14 in [this commit](https://github.com/PHPMailer/PHPMailer/commit/6687a96a18b8f12148881e4ddde795ae477284b0). ### Workarounds Manually strip line breaks from email addresses before passing them to PHPMailer. ### References https://nvd.nist.gov/vuln/detail/CVE-2015-8476 ### For more information If you have any questions or comments about this advisory: * Open a private issue in [the PHPMailer project](https://github.com/PHPMailer/PHPMailer)
References: https://github.com/PHPMailer/PHPMailer/security/advisories/GHSA-738m-f33v-qc2r, https://nvd.nist.gov/vuln/detail/CVE-2015-8476, https://github.com/PHPMailer/PHPMailer/commit/6687a96a18b8f12148881e4ddde795ae477284b0, https://github.com/FriendsOfPHP/security-advisories/blob/master/phpmailer/phpmailer/CVE-2015-8476.yaml, https://github.com/PHPMailer/PHPMailer/releases/tag/v5.2.14, http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177130.html, http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177139.html, http://www.debian.org/security/2015/dsa-3416, http://www.openwall.com/lists/oss-security/2015/12/04/5, http://www.openwall.com/lists/oss-security/2015/12/05/1, http://www.securityfocus.com/bid/78619
Affected packages
Package
Name: phpmailer/phpmailer
Purl: pkg:composer/phpmailer/phpmailer
Affected ranges
Type: ECOSYSTEM
Events:
