Vulnerability Description
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zend | Zend Framework | <= 2.4.10 |
| Zend | Zend-Mail | <= 2.4.10 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/95144Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037539
- https://framework.zend.com/security/advisory/ZF2016-04ExploitTechnical DescriptionVendor Advisory
- https://legalhackers.com/advisories/ZendFramework-Exploit-ZendMail-Remote-Code-EExploitTechnical DescriptionThird Party Advisory
- https://security.gentoo.org/glsa/201804-10
- https://www.exploit-db.com/exploits/40979/
- https://www.exploit-db.com/exploits/40986/
- https://www.exploit-db.com/exploits/42221/
- http://www.securityfocus.com/bid/95144Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037539
- https://framework.zend.com/security/advisory/ZF2016-04ExploitTechnical DescriptionVendor Advisory
- https://legalhackers.com/advisories/ZendFramework-Exploit-ZendMail-Remote-Code-EExploitTechnical DescriptionThird Party Advisory
- https://security.gentoo.org/glsa/201804-10
- https://www.exploit-db.com/exploits/40979/
- https://www.exploit-db.com/exploits/40986/
FAQ
What is CVE-2016-10034?
CVE-2016-10034 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra...
How severe is CVE-2016-10034?
CVE-2016-10034 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-10034?
Check the references section above for vendor advisories and patch information. Affected products include: Zend Zend Framework, Zend Zend-Mail.