View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
12030 | Bug reports | Security | public | 2017-01-04 17:41 | 2017-01-12 13:02 |
Reporter | jsalmeron | Assigned To | |||
Priority | none | Severity | partial_block | ||
Status | closed | Resolution | fixed | ||
Product Version | 2.55.x | ||||
Fixed in Version | 2.58.x | ||||
Summary | 12030: PHPMailer security issue | ||||
Description | On 25.12.2016 a security issue (CVE-2016-10033) was found in the PHPMailer component for versions lower than 5.20. Could you confirm if the application is vulnerable? More info: https://legalhackers.com/advisories/PHPMailer-Exploit-Remote-Code-Exec-CVE-2016-10033-Vuln.html | ||||
Tags | No tags attached. | ||||
Bug heat | 260 | ||||
Complete LimeSurvey version number (& build) | 2.55.x | ||||
I will donate to the project if issue is resolved | No | ||||
Browser | |||||
Database type & version | mysql | ||||
Server OS (if known) | Linux | ||||
Webserver software & version (if known) | Apache | ||||
PHP Version | any | ||||
https://github.com/LimeSurvey/LimeSurvey/commit/31f2fb7e6c6f455e165cdda6a7fa4f9e68ecda94 |
|
The current lime 170104 version contains 5.2.19! The correct version is 5.2.21! Not 5.2.19, this is still not save. |
|
Oh right ... Think https://github.com/LimeSurvey/LimeSurvey/pull/616 was merged |
|
Is there any ETA for this issue to be fixed? We would need to upgrade as soon as possible. Thanks |
|
New version released. |
|
So LimeSurvey 2.58.1 build 170113 is now on PHPMailer 5.2.21. BTW: Why 170113 on a 12th Jan release? 5.2.22 is out since 5th Jan. 2017. Changelog PHPMailer As least for multiuser LS installations the threat is high. |
|
@jelo : already reported for 5.2.22 release. We are sure there only admin who can broke security. |
|
I am sure that not even admins can break security. |
|
<img src="/../../config.php" /> seems the test done https://github.com/PHPMailer/PHPMailer/commit/48e8cac06775d2696cbcfe9b950c484926cc9da3#diff-740525a76c801bb681f23f901454d72bR1014 But : think send are broken here |
|
LimeSurvey: master 1824438e 2017-01-09 16:16 Committer: GitHub Details Diff |
Merge pull request #616 from tuxmaster/master Update to 5.2.21 to fix CVE-2016-10045 |
Affected Issues 12030 |
|
mod - application/third_party/phpmailer/VERSION | Diff File | ||
mod - application/third_party/phpmailer/class.phpmailer.php | Diff File | ||
mod - application/third_party/phpmailer/class.pop3.php | Diff File | ||
mod - application/third_party/phpmailer/class.smtp.php | Diff File |
Date Modified | Username | Field | Change |
---|---|---|---|
2017-01-04 17:41 | jsalmeron | New Issue | |
2017-01-05 08:37 | DenisChenu | Assigned To | => markusfluer |
2017-01-05 08:37 | DenisChenu | Status | new => closed |
2017-01-05 08:37 | DenisChenu | Resolution | open => no change required |
2017-01-05 08:37 | DenisChenu | Note Added: 42626 | |
2017-01-05 10:02 | asshank | Note Added: 42628 | |
2017-01-05 11:09 | DenisChenu | Status | closed => confirmed |
2017-01-05 11:09 | DenisChenu | Note Added: 42629 | |
2017-01-09 11:04 | jsalmeron | Note Added: 42674 | |
2017-01-09 15:17 | c_schmitz | Changeset attached | => LimeSurvey master 1824438e |
2017-01-09 15:17 | c_schmitz | Status | confirmed => resolved |
2017-01-09 15:17 | c_schmitz | Resolution | no change required => fixed |
2017-01-09 15:17 | c_schmitz | Fixed in Version | => 2.58.x |
2017-01-12 12:10 | c_schmitz | Status | resolved => closed |
2017-01-12 12:10 | c_schmitz | Note Added: 42685 | |
2017-01-12 12:34 | jelo | Note Added: 42690 | |
2017-01-12 12:37 | DenisChenu | Note Added: 42691 | |
2017-01-12 12:52 | c_schmitz | Note Added: 42692 | |
2017-01-12 13:02 | DenisChenu | Note Added: 42693 |