IM
IronMonkey Threat Research

CVE-2018-19518 HIGH

Published: 2018-11-25 | Last Modified: 2026-06-17 | Status: Modified

Description

University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of the imap_rimap function in c-client/imap4r1.c and the tcp_aopen function in osdep/unix/tcp_unix.c) without preventing argument injection, which might allow remote attackers to execute arbitrary OS commands if the IMAP server name is untrusted input (e.g., entered by a user of a web application) and if rsh has been replaced by a program with different argument semantics. For example, if rsh is a link to ssh (as seen on Debian and Ubuntu systems), then the attack can use an IMAP server name containing a "-oProxyCommand" argument.

Additional Descriptions (1)

La versión 2007f de University of Washington IMAP Toolkit en UNIX, tal y como se utiliza en imap_open() en PHP y otros productos, lanza un comando rsh (por medio de la función imap_rimap en c-client/imap4r1.c y la función tcp_aopen en osdep/unix/tcp_unix.c) sin prevenir una inyección de argumentos. Esto podría permitir a los atacantes remotos ejecutar comandos arbitrarios del sistema operativo si el nombre del servidor IMAP son entradas no fiables (por ejemplo, si son introducidos por un usuario de una aplicación web) y si rsh ha sido reemplazado por un programa con semánticas de argumentos diversas. Por ejemplo, si rsh es un enlace a ssh (como es el caso de los sistemas Debian y Ubuntu), el ataque puede utilizar un nombre del servidor IMAP que contenga un argumento "-oProxyCommand".

CVSS Metrics

Base Score: 7.5 (HIGH)

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack VectorNETWORK
Attack ComplexityHIGH
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 1.6

Impact Score: 5.9

Base Score: 8.5 (HIGH)

AV:N/AC:M/Au:S/C:C/I:C/A:C

Access VectorNETWORK
Access ComplexityMEDIUM
AuthenticationSINGLE
Confidentiality ImpactCOMPLETE
Integrity ImpactCOMPLETE
Availability ImpactCOMPLETE

Source: [email protected]

Type: Primary

Exploitability Score: 6.8

Impact Score: 10.0

Weaknesses

Source Type Description
[email protected] Primary
en CWE-88

Affected Products

Vendor Product Version Update Type
php php * <built-in method update of dict object at 0x7cfc0c49db80> Application
php php * <built-in method update of dict object at 0x7cfbd4cbc040> Application
php php * <built-in method update of dict object at 0x7cfc0c49f080> Application
php php * <built-in method update of dict object at 0x7cfc0c2bf5c0> Application
debian debian_linux 8.0 <built-in method update of dict object at 0x7cfc0c4f4dc0> Operating System
debian debian_linux 9.0 <built-in method update of dict object at 0x7cfc0c4f5880> Operating System
uw-imap_project uw-imap 2007f <built-in method update of dict object at 0x7cfc0c2bdd00> Application
canonical ubuntu_linux 16.04 <built-in method update of dict object at 0x7cfbd4cbd140> Operating System
canonical ubuntu_linux 18.04 <built-in method update of dict object at 0x7cfc0c4f70c0> Operating System
canonical ubuntu_linux 19.04 <built-in method update of dict object at 0x7cfc0c4f6e40> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:php:php:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:uw-imap_project:uw-imap:2007f:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
Yes cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
Yes cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*

References

Notification
Message here