Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora: 2021-ecf4fed550 Critical: PhpMailer Object Injection Fix

fedora
Calendar Grey May 12, 2021
Dist Fedora Esm H88
This update addresses critical security issues in php-phpmailer6 with a fix for object injection vulnerabilities.
**Version 6.4.1** (April 29th, 2021) * **SECURITY** Fixes CVE-2020-36326, a regression of CVE-2018-19296 object injection introduced in 6.1.8, see SECURITY.md for details * Reject ...

Summary

PHPMailer - A full-featured email creation and transfer class for PHP

Class Features

* Probably the world's most popular code for sending email from PHP!

* Used by many open-source projects:

WordPress, Drupal, 1CRM, SugarCRM, Yii, Joomla! and many more

* Integrated SMTP support - send without a local mail server

* Send emails with multiple To, CC, BCC and Reply-to addresses

* Multipart/alternative emails for mail clients that do not read HTML email

* Add attachments, including inline

* Support for UTF-8 content and 8bit, base64, binary, and quoted-printable

encodings

* SMTP authentication with LOGIN, PLAIN, CRAM-MD5 and XOAUTH2 mechanisms

over SSL and SMTP+STARTTLS transports

* Validates email addresses automatically

* Protect against header injection attacks

* Error messages in 47 languages!

* DKIM and S/MIME signing support

* Compatible with PHP 5.5 and later

* Namespaced to prevent name clashes

* Much more!

Autoloader: /usr/share/php/PHPMailer/PHPMailer6/autoload.php

**Version 6.4.1** (April 29th, 2021) * **SECURITY** Fixes CVE-2020-36326, a

regression of CVE-2018-19296 object injection introduced in 6.1.8, see

SECURITY.md for details * Reject more file paths that look like URLs, matching

RFC3986 spec, blocking URLS using schemes such as `ssh2` * Ensure method

signature consistency in `doCallback` calls * Ukrainian language update * Add

composer scripts for checking coding standards and running tests

* Mon May 3 2021 Remi Collet - 6.4.1-1

- update to 6.4.1

[ 1 ] Bug #1955757 - CVE-2020-36326 php-phpmailer6: Object injection through Phar Deserialization via addAttachment with a UNC pathname [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1955757

su -c 'dnf upgrade --advisory FEDORA-2021-ecf4fed550' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 33
Version: 6.4.1
Release: 1.fc33
Summary: Full-featured email creation and transfer class for PHP

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here