The lettre library through 0.10.0-alpha for Rust allows arbitrary sendmail option injection via transport/sendmail/mod.rs.
Link | Tags |
---|---|
https://github.com/lettre/lettre | third party advisory product |
https://github.com/RustSec/advisory-db/pull/478/files | third party advisory patch |
https://rustsec.org/advisories/RUSTSEC-2020-0069.html | third party advisory |