Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Wed, 25 Apr 2012 15:06:10 -0600
From: Vincent Danen <>
Subject: CVE request: two flaws fixed in rubygem-mail 2.4.4

Two flaws were corrected in rubygem-mail version 2.4.4:

A file system traversal in file_delivery method [1].

Arbitrary command execution when using exim or sendmail from the commandline [2],[3].


Other references:

Could two CVEs be assigned for these flaws please?

Vincent Danen / Red Hat Security Response Team 

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ