CVE-2009-4023

Publication date 29 November 2009

Last updated 24 July 2024


Ubuntu priority

Description

Argument injection vulnerability in the sendmail implementation of the Mail::Send method (Mail/sendmail.php) in the Mail package 1.1.14 for PEAR allows remote attackers to read and write arbitrary files via a crafted $from parameter, a different vector than CVE-2009-4111.

Status

Package Ubuntu Release Status
php-mail 9.10 karmic
Fixed 1.1.14-1+lenny1build0.9.10.1
9.04 jaunty
Fixed 1.1.14-1+lenny1build0.9.04.1
8.10 intrepid
Fixed 1.1.14-1+lenny1build0.8.10.1
8.04 LTS hardy
Fixed 1.1.6-2+etch1build0.8.04.1
6.06 LTS dapper
Fixed 1.1.6-2+etch1build0.6.06.1

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
php-mail

Access our resources on patching vulnerabilities