The mailSend function in the isMail transport in PHPMailer before 5.2.18, when the Sender property is not set, might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a ” (backslash double quote) in a crafted From address.
Monthly Archives: December 2016
CVE-2016-10034
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a ” (backslash double quote) in a crafted e-mail address.
CVE-2016-10074
The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a ” (backslash double quote) in a crafted e-mail address in the (1) From, (2) ReturnPath, or (3) Sender header.
CVE-2016-10045
The isMail transport in PHPMailer before 5.2.20, when the Sender property is not set, might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-10033.
CVE-2016-10088
The sg implementation in the Linux kernel through 4.9 does not properly restrict write operations in situations where the KERNEL_DS option is set, which allows local users to read or write to arbitrary kernel memory locations or cause a denial of service (use-after-free) by leveraging access to a /dev/sg device, related to block/bsg.c and drivers/scsi/sg.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-9576.
RHSA-2016:2999-1: Low: Red Hat OpenShift Enterprise 2.x – End Of Life Notice
This is the Final notification for the End of Production Phase 1 of Red Hat
OpenShift Enterprise 2.x (2.0, 2.1 and 2.2).
Full Summarized List Of All Government Docs In US Response To Russian Election Hacking
mingw-libpng-1.6.27-1.fc25
MinGW cross compiled libpng 1.6.27 release, fixing a potential security issue. For details, see https://sourceforge.net/p/png-mng/mailman/message/35575076/
mingw-libpng-1.6.27-1.fc24
MinGW cross compiled libpng 1.6.27 release, fixing a potential security issue. For details, see https://sourceforge.net/p/png-mng/mailman/message/35575076/
libpng-1.6.27-1.fc25
libpng 1.6.27 release, fixing a potential security issue. For details, see https://sourceforge.net/p/png-mng/mailman/message/35575076/