[pkg-php-pear] Bug#807265: libphp-phpmailer: CVE-2015-8476: Message Injection Vulnerability
Salvatore Bonaccorso
carnil at debian.org
Sun Dec 6 20:59:32 UTC 2015
Package: libphp-phpmailer
Version: 5.2.9+dfsg-2
Severity: important
Tags: security upstream patch fixed-upstream
Hi,
the following vulnerability was published for libphp-phpmailer.
CVE-2015-8476[0]:
PHPMailer Message Injection Vulnerability
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2015-8476
[1] https://github.com/PHPMailer/PHPMailer/commit/6687a96a18b8f12148881e4ddde795ae477284b0
Please adjust the affected versions in the BTS as needed, in
particular wheezy version not checked.
Regards,
Salvatore
More information about the pkg-php-pear
mailing list