Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2020.2632 libphp-phpmailer security update 3 August 2020 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: libphp-phpmailer Publisher: Debian Operating System: Debian GNU/Linux 9 Impact/Access: Overwrite Arbitrary Files -- Remote/Unauthenticated Resolution: Patch/Upgrade CVE Names: CVE-2020-13625 Reference: ESB-2020.2043 Original Bulletin: https://lists.debian.org/debian-lts-announce/2020/08/msg00004.html - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2306-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Abhijith PA August 01, 2020 https://wiki.debian.org/LTS - - ------------------------------------------------------------------------- Package : libphp-phpmailer Version : 5.2.14+dfsg-2.3+deb9u2 CVE ID : CVE-2020-13625 Debian Bug : 962827 It was discovered that there was an escaping issue in libphp-phpmailer, an email generation utility class for the PHP programming language. The `Content-Type` and `Content-Disposition` headers could have permitted file attachments that bypassed attachment filters which match on filename extensions. For Debian 9 stretch, this problem has been fixed in version 5.2.14+dfsg-2.3+deb9u2. We recommend that you upgrade your libphp-phpmailer packages. For the detailed security status of libphp-phpmailer please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libphp-phpmailer Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS - -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAl8mQ3gACgkQhj1N8u2c KO//lQ//cNjg4k7DZlsBE+ilFtDRb/KyvNJPM6UTXHOe2RkB1Pna22/b6zA+VkEd fDE/dO9gi8/pcLSGAeiUJO0kR70zAH0y/rkEGJN6RfK1lsUs9eUEoEkx/mPXuRy3 WQfElWLDLlDhsqBNPt7ml5HhuKRVpCy0kE5M/BwPsD+TyYg8Mun7+0PvcV8CTZcV 9T0FHu6BG6hPJ7zSHy5+HsOdc83e7T6YpwndGm/Dhz8EtMgMmUhA3qWKrO2vykRz Av+bqsrcsk+3Rtxn/7ERTD/LnwmiP1s0z3ZnjpB6IA/ILS44HyY5dAHf8rd6/Pvm pBUJ9M2oF2JiEhdtxt676XNcbMtYtP9Wy1l6NW+1/zmLI7ZqW0aVpzTGqWGLsFzl 8Oxw4qUTGq2URosz3Xr3qluvxNUhD7hZthUJGWqpI2pd6xKVORtPc0T2XQvUXHv1 Rzwjz7GVlRg/q0y6fcTxRiY1dco/UQbYwiGs1Se1kwf2jWEx+FKpbAOfT4oChqcj CCxQbHla/SITjaowjjSP6XP3boY+iM6tfkxHg92eoUjuFxUlG34nIrWpVbpWvILF 1FwpL8qJOZRxVAMqvb+Ah07tks+ahzrKilvTZEZlGD2ljUpKpDhDZOwG4LkCNZmn pACw9ChqLdXqtc9GdDAh9gjl/Rczh1dVfelzxm9hZK7fAfbbB0I= =2VjE - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBXydgouNLKJtyKPYoAQheLhAAicoK9Jtp0VMTboCNxPrcC4dMB6L7SJTC bqEpx7zuzB0VRXwqn9ZWxeo/HGp6ZBavPftiki14hLt+BdEh1BMOkXfUTwr0cutp Lv0+16bTV9MwJ7cM5rRj4ZpgYSz243E9MbmecWSe7ajZHVKNSL+nQT6I0GuxOSGW P+Aqb+D/nLGJP+ad81cIHZsKGCf1gSE9xt+I+ToSYGvrzeX+bzu9zq0gCRsIU2u4 HbBkNIRS3LmO/qmSc52MYixbDciOYcPQ6/2pvrp2V67NzgteBOXbAPkTMqt+F3j4 hcKpinWDeTFy62RD0Ls2S/zAQ1c3fe5IJ/4icqhof6Gk4zOV9DC/HARwIftrKAg0 30ci+orPCSOw9eX3MWtCX8HzMgVp5hcMDt+SVglx4aU/JyY66fIC2Suvkuzlvriq +KsKkIfRo0SRk4MIpaGslVs9hKbJuHlvrgW4tMX6GrYT4EvPRgOiX+eDBHCmV03R lzqs8q0RHg//DhV/XVpHe3fOF3SXdpCRJUKy7ulLjv69eT92O9zkXzEgOeilTK+f d5U+hg25nLtkswp6sKESJDIkDZVSoGAuoeJQ4a5SiS1ZaV5Ej8e797mNV5AZZ3no +goYNXaevf6MOUc0bZFA7ICJt9NcYB80QKmlUH9tC6tEvA0fXC8xRuLYNE4BKZte /HxNu8Zdv08= =UaZY -----END PGP SIGNATURE-----