CVE-2016-10034

EUVD-2022-5138
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
zendzend_framework
𝑥
≤ 2.4.10
zendzend-mail
𝑥
≤ 2.4.10
zendzend-mail
2.5.0
zendzend-mail
2.5.1
zendzend-mail
2.5.2
zendzend-mail
2.6.0
zendzend-mail
2.6.1
zendzend-mail
2.6.2
zendzend-mail
2.7.0
zendzend-mail
2.7.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libphp-phpmailer
precise
not-affected
trusty
dne
xenial
not-affected
yakkety
not-affected