Remote Command Execution in Ruby Mail Gem Affecting Sendmail Delivery Agent
CVE-2011-0739

Currently unrated

Key Information:

Status
Vendor
CVE Published:
2 February 2011

What is CVE-2011-0739?

The Ruby Mail gem contains a vulnerability within the sendmail delivery agent which permits remote attackers to execute arbitrary commands. This is achieved through the injection of shell metacharacters within an email address, enabling unauthorized command execution in systems utilizing affected versions of the library. It is crucial for developers and system administrators to apply security patches and validate input thoroughly to mitigate risks associated with this vulnerability.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.