From 5f87e21af3760e07109aa0e1132544906c527fd8 Mon Sep 17 00:00:00 2001 From: Marcus Bointon Date: Sat, 24 Dec 2016 00:07:36 +0100 Subject: [PATCH] Update security notes # Conflicts: # src/PHPMailer.php # src/POP3.php # src/SMTP.php --- SECURITY.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/SECURITY.md b/SECURITY.md index 5ff31c34..39b0671f 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -2,7 +2,7 @@ Please disclose any vulnerabilities found responsibly - report any security problems found to the maintainers privately. -PHPMailer versions prior to 5.2.18 (released December 2016) are vulnerable to [CVE-2016-10033](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-10033) a remote code execution vulnerability. +PHPMailer versions prior to 5.2.18 (released December 2016) are vulnerable to [CVE-2016-10033](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-10033) a remote code execution vulnerability, responsibly reported by [Dawid Golunski](https://legalhackers.com). PHPMailer versions prior to 5.2.14 (released November 2015) are vulnerable to [CVE-2015-8476](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-8476) an SMTP CRLF injection bug permitting arbitrary message sending.