{"id":"GHSA-rp63-jfmw-532w","summary":"Mail Gem Improper Input Validation vulnerability","details":"The Mail gem before 2.4.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) sendmail or (2) exim delivery.","aliases":["CVE-2012-2140"],"modified":"2024-12-03T06:00:16.677168Z","published":"2017-10-24T18:33:38Z","database_specific":{"cwe_ids":["CWE-20"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:55:16Z","nvd_published_at":null},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2012-2140"},{"type":"WEB","url":"https://github.com/mikel/mail/commit/39b590ddb08f90ddbe445837359a2c8843e533d0"},{"type":"WEB","url":"https://github.com/mikel/mail/commit/ac56f03bdfc30b379aeecd4ff317d08fdaa328c2"},{"type":"WEB","url":"https://bugzilla.novell.com/show_bug.cgi?id=759092"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=816352"},{"type":"PACKAGE","url":"https://github.com/mikel/mail"},{"type":"WEB","url":"https://github.com/mikel/mail/blob/9beb079c70d236a5ad2e1ba95b2c977e55deb7af/CHANGELOG.rdoc"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080645.html"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080648.html"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080747.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/04/25/8"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/04/26/1"}],"affected":[{"package":{"name":"mail","ecosystem":"RubyGems","purl":"pkg:gem/mail"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.3"}]}],"versions":["1.0.0","1.1.0","1.2.1","1.2.5","1.2.6","1.2.8","1.2.9","1.3.0","1.3.1","1.3.2","1.3.3","1.3.4","1.3.5","1.4.0","1.4.1","1.4.2","1.4.3","1.5.0","1.5.1","1.5.2","1.5.3","1.5.4","1.6.0","2.0.3","2.0.5","2.1.0","2.1.1","2.1.2","2.1.3","2.1.5","2.1.5.1","2.1.5.2","2.1.5.3","2.2.0","2.2.1","2.2.10","2.2.11","2.2.12","2.2.13","2.2.14","2.2.15","2.2.16","2.2.17","2.2.18","2.2.19","2.2.2","2.2.20","2.2.3","2.2.4","2.2.5","2.2.5.1","2.2.5.2","2.2.6","2.2.6.1","2.2.7","2.2.9","2.2.9.1","2.3.0","2.3.2","2.3.3","2.4.0","2.4.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-rp63-jfmw-532w/GHSA-rp63-jfmw-532w.json"}}],"schema_version":"1.9.0"}