CVE-2016-10045
Description
Remote code execution in PHPMailer
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-10045
Vendor advisory: cve@mitre.org — https://legalhackers.com/advisories/PHPMailer-Exploit-Remote-Code-Exec-CVE-2016-10045-Vuln-Patch-Bypass.html
Vendor advisory: cve@mitre.org — https://github.com/PHPMailer/PHPMailer/wiki/About-the-CVE-2016-10033-and-CVE-2016-10045-vulnerabilities
Vendor advisory: cve@mitre.org — https://github.com/PHPMailer/PHPMailer/releases/tag/v5.2.20
Vendor advisory: cve@mitre.org — http://seclists.org/fulldisclosure/2016/Dec/81
Vendor advisory: cve@mitre.org — http://openwall.com/lists/oss-security/2016/12/28/1
Vendor advisory: arch — https://security.archlinux.org/ASA-201701-22
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| arch | fixed | 4.7.1-1 | |
| debian | bookworm | fixed | 0 |
| debian | bullseye | fixed | 0 |
| debian | forky | fixed | 0 |
| debian | sid | fixed | 0 |
| debian | trixie | fixed | 0 |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Packagist | phpmailer/phpmailer | >=5.0.0,<5.2.20 | 5.2.20 |
References
- https://security.archlinux.org/ASA-201701-22
- http://openwall.com/lists/oss-security/2016/12/28/1
- http://packetstormsecurity.com/files/140286/PHPMailer-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/140350/PHPMailer-Sendmail-Argument-Injection.html
- http://seclists.org/fulldisclosure/2016/Dec/81
- http://www.rapid7.com/db/modules/exploit/multi/http/phpmailer_arg_injection
- http://www.securityfocus.com/archive/1/539967/100/0/threaded
- http://www.securityfocus.com/bid/95130
- http://www.securitytracker.com/id/1037533
- https://developer.joomla.org/security-centre/668-20161205-phpmailer-security-advisory.html
- https://github.com/PHPMailer/PHPMailer/releases/tag/v5.2.20
- https://github.com/PHPMailer/PHPMailer/wiki/About-the-CVE-2016-10033-and-CVE-2016-10045-vulnerabilities
- https://legalhackers.com/advisories/PHPMailer-Exploit-Remote-Code-Exec-CVE-2016-10045-Vuln-Patch-Bypass.html
- https://www.exploit-db.com/exploits/40969/
- https://www.exploit-db.com/exploits/40986/
- https://www.exploit-db.com/exploits/42221/
- https://security-tracker.debian.org/tracker/CVE-2016-10045
- https://github.com/PHPMailer/PHPMailer/security/advisories/GHSA-4pc3-96mx-wwc8
- https://nvd.nist.gov/vuln/detail/CVE-2016-10045
- https://github.com/FriendsOfPHP/security-advisories/blob/master/phpmailer/phpmailer/CVE-2016-10045.yaml
- https://github.com/PHPMailer/PHPMailer
- https://www.exploit-db.com/exploits/40969
- https://www.exploit-db.com/exploits/40986
- https://www.exploit-db.com/exploits/42221
CWEs
CWE-77
Verify integrity in audit chain (admin only). AS-IS.