{
  "modified": "2025-08-09T19:01:27Z",
  "published": "2010-03-27T19:07:11Z",
  "id": "CVE-2010-1132",
  "details": "The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacters in the RCPT TO field of an email message.",
  "references": [
    {
      "type": "ADVISORY",
      "url": "http://secunia.com/advisories/38840"
    },
    {
      "type": "ADVISORY",
      "url": "http://secunia.com/advisories/38956"
    },
    {
      "type": "ADVISORY",
      "url": "http://secunia.com/advisories/39265"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.debian.org/security/2010/dsa-2021"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.vupen.com/english/advisories/2010/0559"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.vupen.com/english/advisories/2010/0683"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.vupen.com/english/advisories/2010/0837"
    },
    {
      "type": "EVIDENCE",
      "url": "http://archives.neohapsis.com/archives/fulldisclosure/2010-03/0139.html"
    },
    {
      "type": "EVIDENCE",
      "url": "http://www.exploit-db.com/exploits/11662"
    },
    {
      "type": "EVIDENCE",
      "url": "http://www.securityfocus.com/bid/38578"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=572117"
    },
    {
      "type": "WEB",
      "url": "http://bugs.debian.org/573228"
    },
    {
      "type": "WEB",
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038535.html"
    },
    {
      "type": "WEB",
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038572.html"
    },
    {
      "type": "WEB",
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038777.html"
    },
    {
      "type": "WEB",
      "url": "http://osvdb.org/62809"
    },
    {
      "type": "WEB",
      "url": "http://www.securitytracker.com/id?1023691"
    },
    {
      "type": "WEB",
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/56732"
    },
    {
      "type": "WEB",
      "url": "https://savannah.nongnu.org/bugs/?29136"
    }
  ]
}
