MGASA-2018-0136
Dashboard / Vulnerabilities / MGASA-2018-0136
Summary: Updated apache-commons-email packages fix security vulnerability
Details: Apache Commons-Email, from version 1.0 to 1.4 inclusive, does not properly validate bounce addresses. If a user of Commons-Email (typically an application programmer) passes unvalidated input as the so-called "Bounce Address", and that input contains line-breaks, then the email details (recipients, contents, etc.) might be manipulated (CVE-2018-1294).
References: https://advisories.mageia.org/MGASA-2018-0136.html, https://bugs.mageia.org/show_bug.cgi?id=22473, https://lists.fedoraproject.org/archives/list/[email protected]/thread/6BK3RDWBGNZHZ6LDJ34DAWVCBE2UGUE3/
Affected packages
Package
Name: apache-commons-email
Purl: pkg:rpm/mageia/apache-commons-email?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
