University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of the imap_rimap function in c-client/imap4r1.c and the tcp_aopen function in osdep/unix/tcp_unix.c) without preventing argument injection, which might allow remote attackers to execute arbitrary OS commands if the IMAP server name is untrusted input (e.g., entered by a user of a web application) and if rsh has been replaced by a program with different argument semantics. For example, if rsh is a link to ssh (as seen on Debian and Ubuntu systems), then the attack can use an IMAP server name containing a "-oProxyCommand" argument.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
18 Apr 2022, 18:12
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:* cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:* cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
|
References | (SECTRACK) http://www.securitytracker.com/id/1042157 - Broken Link | |
References | (UBUNTU) https://usn.ubuntu.com/4160-1/ - Third Party Advisory | |
References | (MLIST) https://lists.debian.org/debian-lts-announce/2021/12/msg00031.html - Mailing List, Third Party Advisory | |
References | (MISC) https://bugs.php.net/bug.php?id=77160 - Vendor Advisory | |
References | (GENTOO) https://security.gentoo.org/glsa/202003-57 - Third Party Advisory | |
References | (BID) http://www.securityfocus.com/bid/106018 - Broken Link | |
References | (MLIST) https://lists.debian.org/debian-lts-announce/2019/03/msg00001.html - Mailing List, Third Party Advisory |
29 Dec 2021, 19:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2018-11-25 10:29
Updated : 2024-02-04 20:03
NVD link : CVE-2018-19518
Mitre link : CVE-2018-19518
CVE.ORG link : CVE-2018-19518
JSON object : View
Products Affected
uw-imap_project
- uw-imap
canonical
- ubuntu_linux
php
- php
debian
- debian_linux
CWE
CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')