Results 1 to 5 of 5
  1. #1
    Join Date
    Oct 2010
    Posts
    3
    Plugin Contributions
    0

    Default Old version of PHPMailer (not a security problem)

    The version of PHPMailer that is bundled with Zen-Cart is very old, and has security issues. My webhost reports that these holes were actively exploited, which caused them to shut down my site. I have successfully replaced the classes with updated versions, which appear to work fine.

  2. #2
    Join Date
    Jan 2004
    Posts
    66,443
    Plugin Contributions
    279

    Default Re: Old version of PHPMailer with security issues

    Which specific "security issues" are you referring to?
    Which specific holes were exploited?
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  3. #3
    Join Date
    Oct 2010
    Posts
    3
    Plugin Contributions
    0

    Default Re: Old version of PHPMailer with security issues

    I'm afraid I don't know exactly which security holes they were talking about and how they were exploited. My webhost reported that the class.phpmailer.php is version 1.73 and the class.smtp.php is version 1.02, while the newest version of both is 5.1.

  4. #4
    Join Date
    Jan 2004
    Posts
    66,443
    Plugin Contributions
    279

    Default Re: Old version of PHPMailer with security issues

    There is a known problem in the original class.phpmailer.php version 1.73 file that was originally published, but when we found out about it, we patched it ourselves, thus removing that vulnerability from Zen Cart.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  5. #5
    Join Date
    Oct 2010
    Posts
    3
    Plugin Contributions
    0

    Default Re: Old version of PHPMailer with security issues

    My webhost (domeneshop.no, one of Norway's largest hosts) provides some further info:

    -----
    The problems here are:The problems here are:

    1) Zen Cart bundles an apparently unmodified PHPMailer 1.02
    (class.smtp.php).

    2) For the purpose of automated version recognition, Zen Cart's
    home-patched class.phpmailer.php pretends to be a vulnerable
    version of PHPMailer: 1.73.

    Since the particular problem with PHPMailer 1.73 appears to be
    patched, the version number should be increased, or the code
    forked to e.g. "Zen Cart PHPMailer" and a separate version
    number tree, in order to avoid confusion. The @version string in
    the comments is unfortunately not helpful, since the proper
    version strings remain unmodified.

    The best by far would be to bundle the current version of
    PHPMailer - our customers report that PHPMailer 5.1 works well
    with Zen Cart.

    For the record, we are very happy that someone has worked hard
    with improving Zen Cart, which just a few months ago was a
    piece of software we recommended our customers avoid, because of
    the plethora of security problems related to the product.

    1) Zen Cart bundles an apparently unmodified PHPMailer 1.02
    (class.smtp.php).

    2) For the purpose of automated version recognition, Zen Cart's
    home-patched class.phpmailer.php pretends to be a vulnerable
    version of PHPMailer: 1.73.

    Since the particular problem with PHPMailer 1.73 appears to be
    patched, the version number should be increased, or the code
    forked to e.g. "Zen Cart PHPMailer" and a separate version
    number tree, in order to avoid confusion. The @version string in
    the comments is unfortunately not helpful, since the proper
    version strings remain unmodified.

    The best by far would be to bundle the current version of
    PHPMailer - our customers report that PHPMailer 5.1 works well
    with Zen Cart.

    For the record, we are very happy that someone has worked hard
    with improving Zen Cart, which just a few months ago was a
    piece of software we recommended our customers avoid, because of
    the plethora of security problems related to the product.

 

 

Similar Threads

  1. v139h USPS NEW version J transit time problem with OLD settings
    By WiccanWitch420 in forum Addon Shipping Modules
    Replies: 12
    Last Post: 4 Aug 2013, 11:25 PM
  2. v138a Shipping address not showing in paypal account on old zc version
    By tushar in forum PayPal Express Checkout support
    Replies: 0
    Last Post: 1 Jun 2012, 07:20 AM
  3. Replies: 4
    Last Post: 25 Jun 2009, 04:50 AM
  4. Deleting an old version of a contribution
    By gob33 in forum Contribution-Writing Guidelines
    Replies: 2
    Last Post: 30 Mar 2009, 10:16 AM
  5. phpmailer linefeed problem
    By patski in forum General Questions
    Replies: 7
    Last Post: 23 May 2006, 06:08 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg