CVE-2009-4023
Gentoo Linux Security Advisory 201412-09
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Argument injection vulnerability in the sendmail implementation of the Mail::Send method (Mail/sendmail.php) in the Mail package 1.1.14 for PEAR allows remote attackers to read and write arbitrary files via a crafted $from parameter, a different vector than CVE-2009-4111.
Vulnerabilidad de inyección de argumento en la implementación sendmail del método Mail::Send (Mail/sendmail.php) en el paquete Mail v1.1.14 para for PEAR, permite a atacantes remotos leer y escribir ficheros de su elección a través de un parámetro $from, es un vector distinto a CVE_2009-4111.
This GLSA contains notification of vulnerabilities found in several Gentoo packages which have been fixed prior to January 1, 2012. The worst of these vulnerabilities could lead to local privilege escalation and remote code execution.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-11-20 CVE Reserved
- 2009-11-28 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/37458 | Third Party Advisory | |
http://svn.php.net/viewvc/pear/packages/Mail/trunk/Mail/sendmail.php?r1=243717&r2=280134 | X_refsource_confirm | |
http://www.openwall.com/lists/oss-security/2009/11/23/8 | Mailing List |
|
https://bugs.gentoo.org/show_bug.cgi?id=294256 | X_refsource_confirm | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/54362 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://pear.php.net/bugs/bug.php?id=16200 | 2024-08-07 |
URL | Date | SRC |
---|---|---|
http://pear.php.net/bugs/bug.php?id=16200&edit=12&patch=quick-fix&revision=1241757412 | 2017-08-17 | |
http://www.securityfocus.com/bid/37081 | 2017-08-17 | |
http://www.vupen.com/english/advisories/2009/3300 | 2017-08-17 |
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00001.html | 2017-08-17 | |
http://secunia.com/advisories/37410 | 2017-08-17 | |
http://www.debian.org/security/2009/dsa-1938 | 2017-08-17 |