CVE-2009-4111
Gentoo Linux Security Advisory 201412-09
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Argument injection vulnerability in Mail/sendmail.php in the Mail package 1.1.14, 1.2.0b2, and possibly other versions for PEAR allows remote attackers to read and write arbitrary files via a crafted $recipients parameter, and possibly other parameters, a different vulnerability than CVE-2009-4023.
Vulnerabilidad de inyección de argumento en Mail/sendmail.php en Mail package v1.1.14, v1.2.0b2, y probablemente otras versiones para PEAR permite a atacantes remotos leer y escribir archivos de su elección a través del parámetro $recipients manipulado y probablemente otros parámetros, una vulnerabilidad diferente que CVE-2009-4023.
This GLSA contains notification of vulnerabilities found in several Gentoo packages which have been fixed prior to January 1, 2012. The worst of these vulnerabilities could lead to local privilege escalation and remote code execution.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-11-28 CVE Reserved
- 2009-11-28 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/37458 | Third Party Advisory | |
http://www.openwall.com/lists/oss-security/2009/11/23/8 | Mailing List |
|
http://www.openwall.com/lists/oss-security/2009/11/28/2 | Mailing List |
|
http://www.securityfocus.com/bid/37395 | Vdb Entry | |
https://bugs.gentoo.org/show_bug.cgi?id=294256 | X_refsource_misc |
URL | Date | SRC |
---|---|---|
http://pear.php.net/bugs/bug.php?id=16200 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00001.html | 2010-12-07 | |
http://www.debian.org/security/2009/dsa-1938 | 2010-12-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pear Search vendor "Pear" | Mail Search vendor "Pear" for product "Mail" | 1.1.14 Search vendor "Pear" for product "Mail" and version "1.1.14" | - |
Affected
| ||||||
Pear Search vendor "Pear" | Mail Search vendor "Pear" for product "Mail" | 1.2.0b2 Search vendor "Pear" for product "Mail" and version "1.2.0b2" | - |
Affected
|