Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 18.04 LTS USN-5956-2 Critical: PHPMailer Execution Risks

ubuntu
Calendar Grey March 15, 2023
Scroller Ubuntu
Essential patch for PHPMailer on Ubuntu. Mitigate execution threats and enhance protection against XSS breaches decisively!
An incomplete fix was discovered in PHPMailer.

Summary

An incomplete fix was discovered in PHPMailer.

Software Description:

- libphp-phpmailer: full featured email transfer class for PHP

Details:

USN-5956-1 fixed vulnerabilities in PHPMailer. It was discovered that the

fix for CVE-2017-11503 was incomplete. This update fixes the problem.

Original advisory details:

 Dawid Golunski discovered that PHPMailer was not properly escaping user

 input data used as arguments to functions executed by the system shell. An

 attacker could possibly use this issue to execute arbitrary code. This

 issue only affected Ubuntu 16.04 ESM. (CVE-2016-10033, CVE-2016-10045)

 It was discovered that PHPMailer was not properly escaping characters

 in certain fields of the code_generator.php example code. An attacker

 could possibly use this issue to conduct cross-site scripting (XSS)

 attacks. This issue was only fixed in Ubuntu 16.04 ESM and Ubuntu 18.04

 ESM. (CVE-2017-11503)

 Yongxiang Li discovered that PHP...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
   libphp-phpmailer 5.2.14+dfsg-2.3+deb9u2ubuntu0.1~esm2

Ubuntu 16.04 ESM:
   libphp-phpmailer                5.2.14+dfsg-1ubuntu0.1~esm2

In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-5956-2

  https://ubuntu.com/security/notices/USN-5956-1

  CVE-2017-11503

Severity
critical
Lowest
Low
Medium
High
Critical

March 15, 2023

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.