CVE-2018-19518
uw-imap - security update
描述
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of the imap_rimap function in c-client/imap4r1.c and the tcp_aopen function in osdep/unix/tcp_unix.c) without preventing argument injection, which might allow remote attackers to execute arbitrary OS commands if the IMAP server name is untrusted input (e.g., entered by a user of a web application) and if rsh has been replaced by a program with different argument semantics. For example, if rsh is a link to ssh (as seen on Debian and Ubuntu systems), then the attack can use an IMAP server name containing a "-oProxyCommand" argument.
如何修補 CVE-2018-19518
要修補 CVE-2018-19518,請將受影響套件升級到下列已修補版本。
- —升級至 5.6.39+dfsg-0+deb8u1 或更新版本
- —升級至 8:2007f~dfsg-6 或更新版本
- —升級至 8:2007f~dfsg-4+deb8u1 或更新版本
- —升級至 8:2007f~dfsg-5+deb9u1 或更新版本
CVE-2018-19518 正在被利用嗎?
可能 — EPSS 為 95.2%,屬於高被利用機率區間,建議優先修補。
受影響套件(4)
- from 0, < 5.6.39+dfsg-0+deb8u1
- from 0, < 8:2007f~dfsg-6
- from 0, < 8:2007f~dfsg-4+deb8u1
- from 0, < 8:2007f~dfsg-5+deb9u1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |