CVE-2005-3883 Information

Share on:

Description

CRLF injection vulnerability in the mb_send_mail function in PHP before 5.1.0 might allow remote attackers to inject arbitrary e-mail headers via line feeds (LF) in the \To\ address argument.

Reference

ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc http://bugs.php.net/bug.php?id=35307 http://rhn.redhat.com/errata/RHSA-2006-0276.html http://secunia.com/advisories/17763 http://secunia.com/advisories/18054 http://secunia.com/advisories/18198 http://secunia.com/advisories/19832 http://secunia.com/advisories/20210 http://secunia.com/advisories/20951 http://securitytracker.com/id?1015296 http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm http://www.mandriva.com/security/advisories?name=MDKSA-2005:238 http://www.php.net/release_5_1_0.php http://www.securityfocus.com/archive/1/419504/100/0/threaded http://www.securityfocus.com/bid/15571 http://www.turbolinux.com/security/2006/TLSA-2006-38.txt http://www.vupen.com/english/advisories/2006/2685 https://exchange.xforce.ibmcloud.com/vulnerabilities/23270 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A10332 https://www.ubuntu.com/usn/usn-232-1/