Multiple Vendor Mail Reply-To Field...

- AV AC AU C I A
发布: 2000-11-01
修订: 2025-04-13

mail is a simple console e-mail client. A vulnerability exists in several vendors' distributions of this program. An attacker can compose an email message with a carefully-formed string in the Reply-To: field which includes shell meta-characters, and send it to a victim/recipient. Upon receipt of this message, the recipient might normally see the dangerous text in the Reply-to field and delete the message without responding. However, the field can be formed in such a way that these extra characters are concealed. By including a series of ^H characters, the attacker can affect the text in the field as it is displayed on the recipient's screen. As a result, the victim has no visible indication that the message variables (eg, from and reply-to) are malformed. If the message elicits a response from the user, the contents of the reply-to field will be interpreted as a reference to a pre-existing file in /tmp, placed earlier by the attacker, which can contain arbitrary shell commands....

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息