GHSA-qc36-q22q-cjw3
Dashboard / Vulnerabilities / GHSA-qc36-q22q-cjw3
GHSA-qc36-q22q-cjw3
Summary: SMTP command injection in lettre
Details: ### Impact Affected versions of lettre allowed SMTP command injection through an attacker's controlled message body. The module for escaping lines starting with a period wouldn't catch a period that was placed after a double CRLF sequence, allowing the attacker to end the current message and write arbitrary SMTP commands after it. ### Fix The flaw is fixed by correctly handling consecutive CRLF sequences. ### References * [RUSTSEC-2021-0069](https://rustsec.org/advisories/RUSTSEC-2021-0069.html)
References: https://github.com/lettre/lettre/security/advisories/GHSA-qc36-q22q-cjw3, https://github.com/lettre/lettre/pull/627/commits/93458d01fed0ec81c0e7b4e98e6f35961356fae2, https://github.com/lettre/lettre/commit/8bfc20506cc5e098fe6eb3d1cafe3bea791215ce, https://github.com/lettre/lettre, https://rustsec.org/advisories/RUSTSEC-2021-0069.html
Affected packages
Package
Name: lettre
Purl: pkg:cargo/lettre
Affected ranges
Type: SEMVER
Events:
