Unrated severityNVD Advisory· Published Nov 29, 2009· Updated Apr 23, 2026
CVE-2009-4023
CVE-2009-4023
Description
Argument injection vulnerability in the sendmail implementation of the Mail::Send method (Mail/sendmail.php) in the Mail package 1.1.14 for PEAR allows remote attackers to read and write arbitrary files via a crafted $from parameter, a different vector than CVE-2009-4111.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
12- pear.php.net/bugs/bug.phpnvdPatchVendor Advisory
- www.securityfocus.com/bid/37081nvdPatch
- www.vupen.com/english/advisories/2009/3300nvdPatch
- pear.php.net/bugs/bug.phpnvdExploitPatchVendor Advisory
- secunia.com/advisories/37410nvdVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2010-11/msg00001.htmlnvd
- secunia.com/advisories/37458nvd
- svn.php.net/viewvc/pear/packages/Mail/trunk/Mail/sendmail.phpnvd
- www.debian.org/security/2009/dsa-1938nvd
- www.openwall.com/lists/oss-security/2009/11/23/8nvd
- bugs.gentoo.org/show_bug.cginvd
- exchange.xforce.ibmcloud.com/vulnerabilities/54362nvd
News mentions
0No linked articles in our index yet.