CVE-2010-1132
Publication date 27 March 2010
Last updated 24 July 2024
Ubuntu priority
Description
The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacters in the RCPT TO field of an email message.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| spamass-milter | 11.10 oneiric |
Not affected
|
| 11.04 natty |
Not affected
|
|
| 10.10 maverick |
Not affected
|
|
| 10.04 LTS lucid |
Not affected
|
|
| 9.10 karmic |
Fixed 0.3.1-8+lenny1build0.9.10.1
|
|
| 9.04 jaunty |
Fixed 0.3.1-8+lenny1build0.9.04.1
|
|
| 8.10 intrepid | Ignored end of life, was needed | |
| 8.04 LTS hardy | Ignored end of life | |
| 6.06 LTS dapper | Ignored end of life |
Notes
Patch details
| Package | Patch details |
|---|---|
| spamass-milter |