CVE-2016-10034

The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
zendzend_framework
𝑥
≤ 2.4.10
zendzend-mail
𝑥
≤ 2.4.10
zendzend-mail
2.5.0
zendzend-mail
2.5.1
zendzend-mail
2.5.2
zendzend-mail
2.6.0
zendzend-mail
2.6.1
zendzend-mail
2.6.2
zendzend-mail
2.7.0
zendzend-mail
2.7.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libphp-phpmailer
yakkety
not-affected
xenial
not-affected
trusty
dne
precise
not-affected