GHSA-r9mw-gwx9-v3h5
Dashboard / Vulnerabilities / GHSA-r9mw-gwx9-v3h5
Summary: zend-mail remote code execution via Sendmail adapter
Details: The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address.
References: https://nvd.nist.gov/vuln/detail/CVE-2016-10034, https://framework.zend.com/security/advisory/ZF2016-04, https://github.com/zendframework/zend-mail, https://legalhackers.com/advisories/ZendFramework-Exploit-ZendMail-Remote-Code-Exec-CVE-2016-10034-Vuln.html, https://security.gentoo.org/glsa/201804-10, https://www.exploit-db.com/exploits/40979, https://www.exploit-db.com/exploits/40986, https://www.exploit-db.com/exploits/42221, http://www.securityfocus.com/bid/95144, http://www.securitytracker.com/id/1037539
Affected packages
Package
Name: zendframework/zend-mail
Purl: pkg:composer/zendframework/zend-mail
Affected ranges
Type: ECOSYSTEM
Events:
