SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  SpamAssassin Milter Plugin Remote Command Execution

Category: SMTP      

The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacters in the RCPT TO field of an email message.

References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1132


Relevant Information