First published: Sun Nov 25 2018(Updated: )
Fixed bug (imap_open allows to run arbitrary shell commands via mailbox parameter). (CVE-2018-19518)
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/php-imap | <5.4.6-0ubuntu5.1 | 5.4.6-0ubuntu5.1 |
ubuntu/php7.0 | <7.0.33 | 7.0.33 |
ubuntu/php7.0 | <7.0.33-0ubuntu0.16.04.1 | 7.0.33-0ubuntu0.16.04.1 |
ubuntu/php7.2 | <7.2.15-0ubuntu0.18.04.1 | 7.2.15-0ubuntu0.18.04.1 |
ubuntu/php7.2 | <7.2.15-0ubuntu0.18.20.1 | 7.2.15-0ubuntu0.18.20.1 |
ubuntu/php7.2 | <7.2.15-0ubuntu2 | 7.2.15-0ubuntu2 |
ubuntu/php7.2 | <7.2.13 | 7.2.13 |
ubuntu/php7.3 | <7.3.0 | 7.3.0 |
ubuntu/uw-imap | <8:2007 | 8:2007 |
ubuntu/uw-imap | <8:2007 | 8:2007 |
ubuntu/uw-imap | <8:2007 | 8:2007 |
ubuntu/uw-imap | <8:2007 | 8:2007 |
ubuntu/uw-imap | <8:2007 | 8:2007 |
debian/uw-imap | 8:2007f~dfsg-7 | |
PHP | <7.0.33 | 7.0.33 |
PHP | >=5.6.0<=5.6.38 | |
PHP | >=7.0.0<=7.0.32 | |
PHP | >=7.1.0<=7.1.24 | |
PHP | >=7.2.0<=7.2.12 | |
Debian | =8.0 | |
Debian | =9.0 | |
UW-IMAP | =2007f | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =19.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19518 has a high severity rating due to its ability to execute arbitrary shell commands.
To fix CVE-2018-19518, upgrade to the appropriate remedied versions of affected packages including PHP and UW-IMAP.
Affected versions include various PHP versions before 5.6.39, 7.0.x before 7.0.33, and several other specified UW-IMAP versions.
CVE-2018-19518 impacts products such as PHP and UW-IMAP when using the imap_open function.
Yes, CVE-2018-19518 allows remote attackers to execute arbitrary shell commands, constituting a remote code execution vulnerability.