Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacters in the RCPT TO field of an email message.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SpamAssassin Milter插件mlfi_envrcpt()远程命令注入漏洞
Vulnerability Description
SpamAssassin是一套用于过滤垃圾邮件的解决方案。 Spamassassin所使用的Milter插件中的没有正确地过滤提交给mlfi_envrcpt()函数的输入参数。如果以expand标记(-x选项)运行spamass-milter,就会导致注入并执行恶意命令。
CVSS Information
N/A
Vulnerability Type
N/A