Oval Definition:oval:com.ubuntu.bionic:def:20181294000
Revision Date:2018-03-20Version:1
Title:CVE-2018-1294 on Ubuntu 18.04 LTS (bionic) - untriaged.
Description:If a user of Apache Commons Email (typically an application programmer) passes unvalidated input as the so-called "Bounce Address", and that input contains line-breaks, then the email details (recipients, contents, etc.) might be manipulated. Mitigation: Users should upgrade to Commons-Email 1.5. You can mitigate this vulnerability for older versions of Commons Email by stripping line-breaks from data, that will be passed to Email.setBounceAddress(String).
Family:unixClass:vulnerability
Status:Reference(s):CVE-2018-1294
Platform(s):Ubuntu 18.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 18.04 LTS (bionic) is installed.
  • AND NOT While related to the CVE in some way, the 'commons-email' package in bionic is not affected (note: '1.5-1').
  • BACK