The AMaViS virus scanner 0.2.0-pre4 and earlier allows remote attackers to execute arbitrary commands as root via an infected mail message with shell metacharacters in the reply-to field.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Virus_scanner |
Amavis |
* |
0.2_pre4 (including) |
References