Majordomo 1.94.3 and earlier allows remote attackers to execute arbitrary commands when the advertise or noadvertise directive is used in a configuration file, via shell metacharacters in the Reply-To header.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Majordomo | Great_circle_associates | * | 1.94.3 (including) |