CVE-2015-9097
12.06.2017, 20:29
The mail gem before 2.5.5 for Ruby (aka A Really Ruby Mail Library) is vulnerable to SMTP command injection via CRLF sequences in a RCPT TO or MAIL FROM command, as demonstrated by CRLF sequences immediately before and after a DATA substring.
Vendor | Product | Version |
---|---|---|
mail_project | 𝑥 ≤ 2.5.4 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References