CVE-2016-10034: Command Injection
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10034?
CVE-2016-10034 has been rated as a high severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2016-10034?
To fix CVE-2016-10034, upgrade to zend-mail version 2.7.2 or later, or zend-framework version 2.4.11 or later.
Which versions are affected by CVE-2016-10034?
CVE-2016-10034 affects zend-mail versions prior to 2.7.2, zend-framework versions before 2.4.11, and several specific versions of zend-mail and framework components.
What can attackers do with CVE-2016-10034?
Attackers can exploit CVE-2016-10034 to pass extra parameters to the mail command, which may allow them to execute arbitrary code.
When was CVE-2016-10034 disclosed?
CVE-2016-10034 was disclosed in April 2016.