Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 22.04 LTS: USN-5956-1 Moderate: Code Execution Threats in PHPMailer

ubuntu
Calendar Grey March 15, 2023
Scroller Ubuntu
Numerous vulnerabilities detected in WordPress necessitate urgent patching across multiple Debian releases to address potential threats.
Several security issues were fixed in PHPMailer.

Summary

Several security issues were fixed in PHPMailer.

Software Description:

- libphp-phpmailer: full featured email transfer class for PHP

Details:

Dawid Golunski discovered that PHPMailer was not properly escaping user

input data used as arguments to functions executed by the system shell. An

attacker could possibly use this issue to execute arbitrary code. This

issue only affected Ubuntu 16.04 ESM. (CVE-2016-10033, CVE-2016-10045)

It was discovered that PHPMailer was not properly escaping characters

in certain fields of the code_generator.php example code. An attacker

could possibly use this issue to conduct cross-site scripting (XSS)

attacks. This issue was only fixed in Ubuntu 16.04 ESM and Ubuntu 18.04

ESM. (CVE-2017-11503)

Yongxiang Li discovered that PHPMailer was not properly converting

relative paths provided as user input when adding attachments to messages,

which could lead to relative image URLs being treated as absolute local

file paths and added ...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
   libphp-phpmailer                6.2.0-2ubuntu0.1~esm1

Ubuntu 20.04 LTS:
   libphp-phpmailer                6.0.6-0.1ubuntu0.1~esm1

Ubuntu 18.04 LTS:
   libphp-phpmailer 5.2.14+dfsg-2.3+deb9u2ubuntu0.1~esm1

Ubuntu 16.04 ESM:
   libphp-phpmailer                5.2.14+dfsg-1ubuntu0.1~esm1

In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-5956-1

  CVE-2016-10033, CVE-2016-10045, CVE-2017-11503, CVE-2017-5223,

  CVE-2018-19296, CVE-2020-13625, CVE-2021-3603

Severity
important
Lowest
Low
Medium
High
Critical

March 15, 2023

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.