[Secure-testing-team] Bug#807265: libphp-phpmailer: CVE-2015-8476: Message Injection Vulnerability

Salvatore Bonaccorso carnil at debian.org
Sun Dec 6 20:59:32 UTC 2015


Package: libphp-phpmailer
Version: 5.2.9+dfsg-2
Severity: important
Tags: security upstream patch fixed-upstream

Hi,

the following vulnerability was published for libphp-phpmailer.

CVE-2015-8476[0]:
PHPMailer Message Injection Vulnerability

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2015-8476
[1] https://github.com/PHPMailer/PHPMailer/commit/6687a96a18b8f12148881e4ddde795ae477284b0

Please adjust the affected versions in the BTS as needed, in
particular wheezy version not checked.

Regards,
Salvatore



More information about the Secure-testing-team mailing list