SB2016092124 - Mail header injection in Drupal Drupal



SB2016092124 - Mail header injection in Drupal Drupal

Published: September 21, 2016

Security Bulletin ID SB2016092124
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Mail header injection (CVE-ID: N/A)

The vulnerability allows Drupal sited to send unwanted emails.
The weakness is caused by linefeeds and carriage returns left in email headers that leads to including of bogus headers into outgoing email.
Successful exploitation of the vulnerability may result in transmission of unwanted emails.

Remediation

Install update from vendor's website.