CVE-2015-8476
libphp-phpmailer - security update
EPSS 2.0%
描述
Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in class.phpmailer.php or (2) SMTP command to the sendCommand function in class.smtp.php, a different vulnerability than CVE-2012-0796.
如何修補 CVE-2015-8476
要修補 CVE-2015-8476,請將受影響套件升級到下列已修補版本。
- Debian/libphp-phpmailer—升級至 5.2.14+dfsg-1 或更新版本
- Debian/libphp-phpmailer—升級至 5.1-1+deb6u11 或更新版本
- —升級至 5.1-1.1 或更新版本
- —升級至 5.2.14 或更新版本
CVE-2015-8476 正在被利用嗎?
低 — EPSS 為 2.0%,目前沒有觀察到大規模利用活動。
受影響套件(4)
- from 0, < 5.2.14+dfsg-1
- from 0, < 5.1-1+deb6u11
- from 0, < 5.1-1.1
- >= 5.0.0, < 5.2.14