Bug#849365: libphp-phpmailer: CVE-2016-10033

2016-12-29 Thread Salvatore Bonaccorso
Hi, On Wed, Dec 28, 2016 at 11:31:11AM +0100, Salvatore Bonaccorso wrote: > Hi > > On Wed, Dec 28, 2016 at 05:38:04AM +0100, Salvatore Bonaccorso wrote: > > On Mon, Dec 26, 2016 at 10:54:47AM +0100, Salvatore Bonaccorso wrote: > > > Source: libphp-phpmailer > > > Version: 5.2.9+dfsg-2 > > > Sever

Bug#849365: libphp-phpmailer: CVE-2016-10033 (wordpress not vulnerable)

2016-12-28 Thread Craig Small
On Wed, 28 Dec 2016 11:31:11 +0100 Salvatore Bonaccorso wrote: > > > the following vulnerability was published for libphp-phpmailer. > > > > > > CVE-2016-10033[0]: > > > remote code execution I would like to point out that wordpress has an embedded/modified version of PHPmailer in it at wp-includ

Bug#849365: libphp-phpmailer: CVE-2016-10033

2016-12-28 Thread Salvatore Bonaccorso
Hi On Wed, Dec 28, 2016 at 05:38:04AM +0100, Salvatore Bonaccorso wrote: > On Mon, Dec 26, 2016 at 10:54:47AM +0100, Salvatore Bonaccorso wrote: > > Source: libphp-phpmailer > > Version: 5.2.9+dfsg-2 > > Severity: grave > > Tags: security upstream > > Justification: user security hole > > > > Hi,

Bug#849365: libphp-phpmailer: CVE-2016-10033

2016-12-27 Thread Salvatore Bonaccorso
On Mon, Dec 26, 2016 at 10:54:47AM +0100, Salvatore Bonaccorso wrote: > Source: libphp-phpmailer > Version: 5.2.9+dfsg-2 > Severity: grave > Tags: security upstream > Justification: user security hole > > Hi, > > the following vulnerability was published for libphp-phpmailer. > > CVE-2016-10033[

Bug#849365: libphp-phpmailer: CVE-2016-10033

2016-12-26 Thread Salvatore Bonaccorso
Source: libphp-phpmailer Version: 5.2.9+dfsg-2 Severity: grave Tags: security upstream Justification: user security hole Hi, the following vulnerability was published for libphp-phpmailer. CVE-2016-10033[0]: remote code execution Details though at the point of writing this bugreport are not yet