First published: Fri Nov 30 2001(Updated: )
PGPMail.pl 1.31 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) recipient or (2) pgpuserid parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pgpmail.pl | =1.31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0937 is a vulnerability in PGPMail.pl 1.31 that allows remote attackers to execute arbitrary commands via shell metacharacters in specific parameters.
CVE-2001-0937 is considered a high severity vulnerability due to its potential for remote command execution.
To fix CVE-2001-0937, upgrade PGPMail.pl to the latest version or apply patches that validate input parameters to prevent command injection.
CVE-2001-0937 specifically affects version 1.31 of PGPMail.pl.
Yes, CVE-2001-0937 can be exploited remotely by attackers through crafted inputs to the vulnerable parameters.