email_in.pl in Bugzilla 2.23.4 through 3.0.0 allows remote attackers to execute arbitrary commands via the -f (From address) option to the Email::Send::Sendmail function, probably involving shell metacharacters.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bugzilla | Mozilla | 2.4 (including) | 2.4 (including) |
Bugzilla | Mozilla | 2.6 (including) | 2.6 (including) |
Bugzilla | Mozilla | 2.8 (including) | 2.8 (including) |
Bugzilla | Mozilla | 2.9 (including) | 2.9 (including) |
Bugzilla | Mozilla | 2.23.4 (including) | 2.23.4 (including) |
Bugzilla | Mozilla | 3.0.0 (including) | 3.0.0 (including) |