MGASA-2016-0019

Source
https://advisories.mageia.org/MGASA-2016-0019.html
Import Source
https://advisories.mageia.org/MGASA-2016-0019.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2016-0019
Published
2016-01-15T01:52:38Z
Modified
2026-04-16T04:27:54.754613Z
Summary
Updated ruby-mail packages fix security vulnerability
Details

The Mail library does not impose a length limit on email addresses, so an attacker can send a long spam message via a recipient address unless there is a limit on the application's side. The attacker-injected message in the recipient address is processed by the server. This type of vulnerability can be real threats in inquiry forms, member signup forms, or any other application that delivers an email to a user-specified email address (bsc#959129)

References
Credits

Affected packages

Mageia:5 / ruby-mail

Package

Name
ruby-mail
Purl
pkg:rpm/mageia/ruby-mail?arch=source&distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.5.4-9.1.mga5

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2016-0019.json"