FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2011-0739

This CVE name corresponds to:

Entered Topic
2011-02-10 rubygem-mail -- Remote Arbitrary Shell Command Injection Vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2011-0739
Phase Assigned(20110201)

Description

The deliver function in the sendmail delivery agent (lib/mail/network/delivery_methods/sendmail.rb) in Ruby Mail gem 2.2.14 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an e-mail address.

References

Source Reference
MISC https://github.com/mikel/mail/raw/master/patches/20110126_sendmail.patch
CONFIRM http://groups.google.com/group/mail-ruby/browse_thread/thread/e93bbd05706478dd?pli=1
BID 46021
OSVDB 70667
SECUNIA 43077
VUPEN ADV-2011-0233
XF ruby-mail-deliver-command-execution(65010)