CVE-2012-2140
Mail Gem Improper Input Validation vulnerability
EPSS 4.5%
Description
The Mail gem before 2.4.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) sendmail or (2) exim delivery.
How to fix CVE-2012-2140
To remediate CVE-2012-2140, upgrade the affected package to a fixed version below.
- Debian/ruby-mail—upgrade to 2.4.4-1 or later
- RubyGems/mail—upgrade to 2.4.3 or later
Is CVE-2012-2140 being exploited?
Low — EPSS is 4.5%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2.4.4-1
- from 0, < 2.4.3