The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacters in the RCPT TO field of an email message.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2021-2 | New spamass-milter packages fix regression |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 28 May 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Thu, 22 May 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T01:14:06.296Z
Reserved: 2010-03-26T00:00:00
Link: CVE-2010-1132
No data.
Status : Deferred
Published: 2010-03-27T19:07:11.717
Modified: 2025-04-11T00:51:21.963
Link: CVE-2010-1132
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA