CVE-2021-38189
08.08.2021, 06:15
An issue was discovered in the lettre crate before 0.9.6 for Rust. In an e-mail message body, an attacker can place a . character after two <CR><LF> sequences and then inject arbitrary SMTP commands.
Vendor | Product | Version |
---|---|---|
lettre | lettre | 𝑥 < 0.9.6 |
lettre | lettre | 0.10.0:alpha1 |
lettre | lettre | 0.10.0:alpha2 |
lettre | lettre | 0.10.0:alpha3 |
lettre | lettre | 0.10.0:alpha4 |
lettre | lettre | 0.10.0:alpha5 |
lettre | lettre | 0.10.0:beta1 |
lettre | lettre | 0.10.0:beta2 |
lettre | lettre | 0.10.0:beta3 |
lettre | lettre | 0.10.0:beta4 |
lettre | lettre | 0.10.0:rc1 |
lettre | lettre | 0.10.0:rc2 |
𝑥
= Vulnerable software versions
References