CVE-2011-0739

Ruby Mail gem < 2.2.14 - Remote Code Execution via Shell Metacharacters in Email Address

Title source: llm
STIX 2.1

Description

The deliver function in the sendmail delivery agent (lib/mail/network/delivery_methods/sendmail.rb) in Ruby Mail gem 2.2.14 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an e-mail address.

References (7)

Core 7
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0233
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/65010
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/46021
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43077
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/70667

Scores

EPSS 0.0075
EPSS Percentile 73.3%

Details

CWE
CWE-20
Status published
Products (50)
mikel_lindsaar/mail 1.0.0
mikel_lindsaar/mail 1.1.0
mikel_lindsaar/mail 1.2.1
mikel_lindsaar/mail 1.2.5
mikel_lindsaar/mail 1.2.6
mikel_lindsaar/mail 1.2.7
mikel_lindsaar/mail 1.2.8
mikel_lindsaar/mail 1.2.9
mikel_lindsaar/mail 1.3.0
mikel_lindsaar/mail 1.3.1
... and 40 more
Published Feb 02, 2011
Tracked Since Feb 18, 2026