-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Package : libphp-phpmailer Version : 5.1-1.2 CVE ID : CVE-2016-10033 Debian Bug : 849365
Dawid Golunski discovered that PHPMailer, a popular library to send email from PHP applications, allowed a remote attacker to execute code if they were able to provide a crafted Sender address. Note that for this issue also CVE-2016-10045 was assigned, which is a regression in the original patch proposed for CVE-2016-10033. Because the origial patch was not applied in Debian, Debian was not vulnerable to CVE-2016-10045. For Debian 7 "Wheezy", these problems have been fixed in version 5.1-1.2. We recommend that you upgrade your libphp-phpmailer packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQEcBAEBCAAGBQJYZ7+EAAoJEFb2GnlAHawEGcQH/2uKvky6iEJeXsUfSZufZGCH w0dbntixdxU3r723CaTuxovbXzRMj3KGG6+I6Wn+QYQsxkNvgYBWvYItXl50/1al QBvVDST3gOzT81RTYXk9fcAZX22eM6ng6X+8tcxIF2MHxEHUw+LA8TCtLbHLpPzW 0+y61yptRbJEUKDQVW7tsJjrRaLP38zJUuuqdu73ME/e/rDJ/RbktMYynzM7X4it N6QeoT14SkuMfIeWVj2awBIs4+6Rle/279Nf7RcazZ4aAsNJWWPjL6w2M6/BWOyF eMD2W9SYdkEZGs14Bt1GSIHkcSUdJiHsTg80o95FfrORwePCdStXgBaEAkR6Dgk= =sX0Z -----END PGP SIGNATURE-----
