CVE-2011-0739
Ruby Mail gem < 2.2.14 - Remote Code Execution via Shell Metacharacters in Email Address
Title source: llmDescription
The deliver function in the sendmail delivery agent (lib/mail/network/delivery_methods/sendmail.rb) in Ruby Mail gem 2.2.14 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an e-mail address.
References (7)
Core 7
Core References
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0233
Patch x_refsource_confirm
http://groups.google.com/group/mail-ruby/browse_thread/thread/e93bbd05706478dd?pli=1
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/65010
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/46021
Patch x_refsource_misc
https://github.com/mikel/mail/raw/master/patches/20110126_sendmail.patch
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/43077
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/70667
Scores
EPSS
0.0075
EPSS Percentile
73.3%
Details
CWE
CWE-20
Status
published
Products (50)
mikel_lindsaar/mail
1.0.0
mikel_lindsaar/mail
1.1.0
mikel_lindsaar/mail
1.2.1
mikel_lindsaar/mail
1.2.5
mikel_lindsaar/mail
1.2.6
mikel_lindsaar/mail
1.2.7
mikel_lindsaar/mail
1.2.8
mikel_lindsaar/mail
1.2.9
mikel_lindsaar/mail
1.3.0
mikel_lindsaar/mail
1.3.1
... and 40 more
Published
Feb 02, 2011
Tracked Since
Feb 18, 2026