SpamAssassin Milter Plugin 'mlfi_envrcpt()' Remote Arbitrary Command Injection Vulnerability

  Severity: CRITICAL
  CVE Identifier: CVE-2010-1132
  Advisory Date: JUL 21, 2015

  DESCRIPTION

The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacters in the RCPT TO field of an email message.

  TREND MICRO PROTECTION INFORMATION

Apply associated Trend Micro DPI Rules.

  SOLUTION

  Trend Micro Deep Security DPI Rule Number: 1004037

  AFFECTED SOFTWARE AND VERSION

  • georg_greve spamassassin_milter_plugin 0.3.1