Object injection attack in PHPMailer - CVE-2018-19296
Published: December 7, 2018 / Updated: December 7, 2018
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to object injection attack. A remote unauthenticated attacker can send a specially crafted request, conduct object injection attack and execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Debian Linux
Fedora
Ubuntu
Nagios XI
libphp-phpmailer (Ubuntu package)
php-PHPMailer
php-phpmailer6
How to mitigate CVE-2018-19296
Nagios XI - update to 5.6.3
libphp-phpmailer (Ubuntu package) - update to Ubuntu Pro
php-PHPMailer - addressed in versions 5.2.27-1.el6, 5.2.27-1.el7, 5.2.27-1.fc27, 5.2.27-1.fc28, 5.2.27-1.fc29
php-phpmailer6 - addressed in versions 6.0.6-1.fc27, 6.0.6-1.fc28, 6.0.6-1.fc29, 6.4.1-1.fc33, 6.4.1-1.fc34
External References
Related Security Bulletins
- Remote code execution in PHPMailer
- Debian update for libphp-phpmailer
- Multiple vulnerabilities in Nagios XI
- Ubuntu update for libphp-phpmailer
- Ubuntu update for libphp-phpmailer
- Fedora 33 update for php-phpmailer6
- Fedora 34 update for php-phpmailer6
- Fedora 28 update for php-PHPMailer
- Fedora 29 update for php-PHPMailer
- Fedora 27 update for php-PHPMailer
- Fedora EPEL 6 update for php-PHPMailer
- Fedora EPEL 7 update for php-PHPMailer
- Fedora 29 update for php-phpmailer6
- Fedora 27 update for php-phpmailer6
- Fedora 28 update for php-phpmailer6