Name | CVE-2015-9096 |
Description | Net::SMTP in Ruby before 2.4.0 is vulnerable to SMTP command injection via CRLF sequences in a RCPT TO or MAIL FROM command, as demonstrated by CRLF sequences immediately before and after a DATA substring. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more) |
References | DLA-1421-1, DSA-3966-1 |
Debian Bugs | 864860 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
ruby1.8 | source | (unstable) | (unfixed) | |||
ruby1.9.1 | source | (unstable) | (unfixed) | |||
ruby2.1 | source | jessie | 2.1.5-2+deb8u4 | DLA-1421-1 | ||
ruby2.1 | source | (unstable) | (unfixed) | |||
ruby2.3 | source | stretch | 2.3.3-1+deb9u1 | DSA-3966-1 | ||
ruby2.3 | source | (unstable) | 2.3.3-1+deb9u1 | 864860 |
[wheezy] - ruby1.9.1 <no-dsa> (Minor issue, Net::SMTP users should validate data they send too)
[wheezy] - ruby1.8 <no-dsa> (Minor issue, Net::SMTP users should validate data they send too)
https://github.com/ruby/ruby/commit/0827a7e52ba3d957a634b063bf5a391239b9ffee
https://github.com/rubysec/ruby-advisory-db/issues/215