-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2020.2632
                     libphp-phpmailer security update
                               3 August 2020

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           libphp-phpmailer
Publisher:         Debian
Operating System:  Debian GNU/Linux 9
Impact/Access:     Overwrite Arbitrary Files -- Remote/Unauthenticated
Resolution:        Patch/Upgrade
CVE Names:         CVE-2020-13625  

Reference:         ESB-2020.2043

Original Bulletin: 
   https://lists.debian.org/debian-lts-announce/2020/08/msg00004.html

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- - -------------------------------------------------------------------------
Debian LTS Advisory DLA-2306-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                          Abhijith PA
August 01, 2020                               https://wiki.debian.org/LTS
- - -------------------------------------------------------------------------

Package        : libphp-phpmailer
Version        : 5.2.14+dfsg-2.3+deb9u2
CVE ID         : CVE-2020-13625
Debian Bug     : 962827

It was discovered that there was an escaping issue in
libphp-phpmailer, an email generation utility class for the PHP
programming language.

The `Content-Type` and `Content-Disposition` headers could have
permitted file attachments that bypassed attachment filters which
match on filename extensions.

For Debian 9 stretch, this problem has been fixed in version
5.2.14+dfsg-2.3+deb9u2.

We recommend that you upgrade your libphp-phpmailer packages.

For the detailed security status of libphp-phpmailer please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libphp-phpmailer

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
- -----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAl8mQ3gACgkQhj1N8u2c
KO//lQ//cNjg4k7DZlsBE+ilFtDRb/KyvNJPM6UTXHOe2RkB1Pna22/b6zA+VkEd
fDE/dO9gi8/pcLSGAeiUJO0kR70zAH0y/rkEGJN6RfK1lsUs9eUEoEkx/mPXuRy3
WQfElWLDLlDhsqBNPt7ml5HhuKRVpCy0kE5M/BwPsD+TyYg8Mun7+0PvcV8CTZcV
9T0FHu6BG6hPJ7zSHy5+HsOdc83e7T6YpwndGm/Dhz8EtMgMmUhA3qWKrO2vykRz
Av+bqsrcsk+3Rtxn/7ERTD/LnwmiP1s0z3ZnjpB6IA/ILS44HyY5dAHf8rd6/Pvm
pBUJ9M2oF2JiEhdtxt676XNcbMtYtP9Wy1l6NW+1/zmLI7ZqW0aVpzTGqWGLsFzl
8Oxw4qUTGq2URosz3Xr3qluvxNUhD7hZthUJGWqpI2pd6xKVORtPc0T2XQvUXHv1
Rzwjz7GVlRg/q0y6fcTxRiY1dco/UQbYwiGs1Se1kwf2jWEx+FKpbAOfT4oChqcj
CCxQbHla/SITjaowjjSP6XP3boY+iM6tfkxHg92eoUjuFxUlG34nIrWpVbpWvILF
1FwpL8qJOZRxVAMqvb+Ah07tks+ahzrKilvTZEZlGD2ljUpKpDhDZOwG4LkCNZmn
pACw9ChqLdXqtc9GdDAh9gjl/Rczh1dVfelzxm9hZK7fAfbbB0I=
=2VjE
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBXydgouNLKJtyKPYoAQheLhAAicoK9Jtp0VMTboCNxPrcC4dMB6L7SJTC
bqEpx7zuzB0VRXwqn9ZWxeo/HGp6ZBavPftiki14hLt+BdEh1BMOkXfUTwr0cutp
Lv0+16bTV9MwJ7cM5rRj4ZpgYSz243E9MbmecWSe7ajZHVKNSL+nQT6I0GuxOSGW
P+Aqb+D/nLGJP+ad81cIHZsKGCf1gSE9xt+I+ToSYGvrzeX+bzu9zq0gCRsIU2u4
HbBkNIRS3LmO/qmSc52MYixbDciOYcPQ6/2pvrp2V67NzgteBOXbAPkTMqt+F3j4
hcKpinWDeTFy62RD0Ls2S/zAQ1c3fe5IJ/4icqhof6Gk4zOV9DC/HARwIftrKAg0
30ci+orPCSOw9eX3MWtCX8HzMgVp5hcMDt+SVglx4aU/JyY66fIC2Suvkuzlvriq
+KsKkIfRo0SRk4MIpaGslVs9hKbJuHlvrgW4tMX6GrYT4EvPRgOiX+eDBHCmV03R
lzqs8q0RHg//DhV/XVpHe3fOF3SXdpCRJUKy7ulLjv69eT92O9zkXzEgOeilTK+f
d5U+hg25nLtkswp6sKESJDIkDZVSoGAuoeJQ4a5SiS1ZaV5Ej8e797mNV5AZZ3no
+goYNXaevf6MOUc0bZFA7ICJt9NcYB80QKmlUH9tC6tEvA0fXC8xRuLYNE4BKZte
/HxNu8Zdv08=
=UaZY
-----END PGP SIGNATURE-----