PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://github.com/PHPMailer/PHPMailer/releases/tag/v5.2.27 | release notes vendor advisory |
https://lists.debian.org/debian-lts-announce/2018/12/msg00020.html | third party advisory mailing list |
https://www.debian.org/security/2018/dsa-4351 | third party advisory vendor advisory |
https://github.com/PHPMailer/PHPMailer/releases/tag/v6.0.6 | release notes vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KPU66INRFY5BQ3ESVPRUXJR4DXQAFJVT/ | vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3B5WDPGUFNPG4NAZ6G4BZX43BKLAVA5B/ | vendor advisory |