CVE-2012-2139: Path Traversal
A flaw was corrected in rubygem-mail version 2.4.4:
A file system traversal in filedelivery method [1].
[1] https://github.com/mikel/mail/commit/29aca25218e4c82991400eb9b0c933626aefc98f
Other sources
Directory traversal vulnerability in lib/mail/network/deliverymethods/filedelivery.rb in the Mail gem before 2.4.4 for Ruby allows remote attackers to read arbitrary files via a .. (dot dot) in the to parameter.
Directory traversal vulnerability in lib/mail/network/deliverymethods/filedelivery.rb in the Mail gem before 2.4.4 for Ruby allows remote attackers to read arbitrary files via a .. (dot dot) in the to parameter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2139?
CVE-2012-2139 has been assigned a high severity due to the file system traversal vulnerability in rubygem-mail.
How do I fix CVE-2012-2139?
To fix CVE-2012-2139, upgrade rubygem-mail to version 2.4.4 or later.
What versions are affected by CVE-2012-2139?
CVE-2012-2139 affects versions of rubygem-mail prior to 2.4.4.
Is CVE-2012-2139 a remote vulnerability?
Yes, CVE-2012-2139 can be exploited remotely due to the vulnerabilities in the file_delivery method.
What type of vulnerability is CVE-2012-2139?
CVE-2012-2139 is a file system traversal vulnerability.