Debian Security Advisory

DLA-363-1 libphp-phpmailer -- LTS security update

Date Reported:
08 Dec 2015
Affected Packages:
libphp-phpmailer
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 807265.
In Mitre's CVE dictionary: CVE-2015-8476.
More information:

It was discovered that there was a header injection vulnerability in libphp-phpmailer, an email transfer library for PHP.

For Debian 6 Squeeze, this issue has been fixed in libphp-phpmailer version 5.1-1+deb6u11.