CVE-2015-9096CRLF Injection in Ruby

Severity
6.1MEDIUMNVD
EPSS
1.6%
top 18.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 12
Latest updateMay 14

Description

Net::SMTP in Ruby before 2.4.0 is vulnerable to SMTP command injection via CRLF sequences in a RCPT TO or MAIL FROM command, as demonstrated by CRLF sequences immediately before and after a DATA substring.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

NVDruby-lang/ruby2.4.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-2h3c-5vqm-gqfh: Net::SMTP in Ruby before 22022-05-14
CVEList
CVE-2015-9096: Net::SMTP in Ruby before 22017-06-12
OSV
CVE-2015-9096: Net::SMTP in Ruby before 22017-06-12

📋Vendor Advisories

2
Ubuntu
Ruby vulnerabilities2017-07-25
Red Hat
ruby: SMTP command injection via CRLF sequences in RCPT TO or MAIL FROM commands in Net::SMTP2017-06-12

💬Community

2
Bugzilla
CVE-2015-9096 ruby: SMTP command injection via CRLF sequences in RCPT TO or MAIL FROM commands in Net::SMTP2017-06-15
Bugzilla
CVE-2015-9096 ruby: SMTP command injection via CRLF sequences in RCPT TO or MAIL FROM commands in Net::SMTP [fedora-all]2017-06-15
CVE-2015-9096 — CRLF Injection in Ruby-lang Ruby | cvebase