Name | CVE-2007-3215 |
Description | PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execute arbitrary shell commands via shell metacharacters in the SendmailSend function in class.phpmailer.php. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-1315-1 |
Debian Bugs | 429179, 429190, 429191, 429192, 429193, 429194, 429195, 429196, 429197, 504253, 504255 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
glpi (PTS) | jessie | 0.84.8+dfsg.1-1 | fixed |
libphp-phpmailer (PTS) | jessie, jessie (lts) | 5.2.9+dfsg-2+deb8u6 | fixed |
stretch (security), stretch (lts), stretch | 5.2.14+dfsg-2.3+deb9u2 | fixed | |
buster | 6.0.6-0.1 | fixed | |
bullseye | 6.2.0-2 | fixed | |
bookworm | 6.6.3-1 | fixed | |
sid, trixie | 6.9.1-1 | fixed | |
wordpress (PTS) | jessie, jessie (lts) | 4.1.35+dfsg-0+deb8u1 | fixed |
stretch (security), stretch (lts), stretch | 4.7.23+dfsg-0+deb9u1 | fixed | |
buster (security), buster, buster (lts) | 5.0.21+dfsg1-0+deb10u1 | fixed | |
bullseye (security), bullseye | 5.7.11+dfsg1-0+deb11u1 | fixed | |
bookworm (security), bookworm | 6.1.6+dfsg1-0+deb12u1 | fixed | |
sid, trixie | 6.6.1+dfsg1-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
egroupware | source | (unstable) | (not affected) | |||
flyspray | source | sarge | (not affected) | |||
flyspray | source | etch | (not affected) | |||
flyspray | source | (unstable) | 0.9.8-12 | 429191, 429195 | ||
glpi | source | etch | (not affected) | |||
glpi | source | (unstable) | 0.68.3.2-1 | 429192 | ||
ipplan | source | (unstable) | 4.85-2 | 429193 | ||
knowledgeroot | source | etch | (not affected) | |||
knowledgeroot | source | (unstable) | 0.9.8.2-2 | 429196 | ||
libphp-phpmailer | source | etch | 1.73-2etch1 | DSA-1315-1 | ||
libphp-phpmailer | source | (unstable) | 1.73-4 | high | 429179 | |
mahara | source | lenny | 1.0.4-3 | |||
mahara | source | (unstable) | 1.0.5-2 | 504253 | ||
moodle | source | (unstable) | 1.8.2-2 | 429190 | ||
owl-dms | source | etch | (not affected) | |||
owl-dms | source | (unstable) | 0.94-2 | 429197 | ||
phpgroupware | source | etch | (not affected) | |||
phpgroupware | source | (unstable) | 0.9.16.012+dfsg-9 | medium | 504255 | |
wordpress | source | etch | (not affected) | |||
wordpress | source | (unstable) | 2.2.1-1 | 429194 |
[etch] - flyspray <not-affected> (Vulnerable code not)
[sarge] - flyspray <not-affected> (Vulnerable code not included)
[etch] - knowledgeroot <not-affected> (Vulnerable code not used)
[etch] - owl-dms <not-affected> (Vulnerable code not used)
[etch] - glpi <not-affected> (Vulnerable code not used)
[etch] - wordpress <not-affected> (Vulnerable code not present)
[etch] - phpgroupware <not-affected> (bug #504255; Vulnerable code not used)
- egroupware <not-affected> (bug #504283; Vulnerable code not used)