{"id":"GHSA-cj92-c4fj-w9c5","summary":"Mail Gem Path Traversal vulnerability","details":"Directory traversal vulnerability in `lib/mail/network/delivery_methods/file_delivery.rb` in the Mail gem before 2.4.4 for Ruby allows remote attackers to read arbitrary files via a `..` (dot dot) in the to parameter.","aliases":["CVE-2012-2139"],"modified":"2024-12-03T06:08:57.952649Z","published":"2017-10-24T18:33:38Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-06-16T21:31:54Z","nvd_published_at":"2012-07-18T18:55:01Z","cwe_ids":["CWE-22"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2012-2139"},{"type":"WEB","url":"https://github.com/mikel/mail/commit/29aca25218e4c82991400eb9b0c933626aefc98f"},{"type":"WEB","url":"https://bugzilla.novell.com/show_bug.cgi?id=759092"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=816352"},{"type":"PACKAGE","url":"https://github.com/mikel/mail"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080645.html"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080648.html"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080747.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/04/25/8"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/04/26/1"}],"affected":[{"package":{"name":"mail","ecosystem":"RubyGems","purl":"pkg:gem/mail"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.4"}]}],"versions":["1.0.0","1.1.0","1.2.1","1.2.5","1.2.6","1.2.8","1.2.9","1.3.0","1.3.1","1.3.2","1.3.3","1.3.4","1.3.5","1.4.0","1.4.1","1.4.2","1.4.3","1.5.0","1.5.1","1.5.2","1.5.3","1.5.4","1.6.0","2.0.3","2.0.5","2.1.0","2.1.1","2.1.2","2.1.3","2.1.5","2.1.5.1","2.1.5.2","2.1.5.3","2.2.0","2.2.1","2.2.10","2.2.11","2.2.12","2.2.13","2.2.14","2.2.15","2.2.16","2.2.17","2.2.18","2.2.19","2.2.2","2.2.20","2.2.3","2.2.4","2.2.5","2.2.5.1","2.2.5.2","2.2.6","2.2.6.1","2.2.7","2.2.9","2.2.9.1","2.3.0","2.3.2","2.3.3","2.4.0","2.4.1","2.4.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-cj92-c4fj-w9c5/GHSA-cj92-c4fj-w9c5.json"}}],"schema_version":"1.9.0"}