Skip to content
This repository has been archived by the owner on Nov 17, 2021. It is now read-only.

Clarify CVE / security fix #847

Merged
merged 1 commit into from Dec 29, 2016
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Jump to
Jump to file
Failed to load files.
Diff view
Diff view
6 changes: 5 additions & 1 deletion CHANGES
Expand Up @@ -4,7 +4,11 @@ Changelog
5.4.5 (2016-XX-XX)
------------------

* fixed CVE-2016-10033 and CVE-2016-10045
* SECURITY FIX: fixed CVE-2016-10074 by disallowing potentially unsafe shell characters

Prior to 5.4.5, the mail transport (Swift_Transport_MailTransport) was vulnerable to passing
arbitrary shell arguments if the "From", "ReturnPath" or "Sender" header came
from a non-trusted source, potentially allowing Remote Code Execution
* deprecated the mail transport

5.4.4 (2016-11-23)
Expand Down