Forums / Upgrading from 1.3.x to 1.3.9 / 2008 PHPMailer v1.7.2 Vunerability Patch

2008 PHPMailer v1.7.2 Vunerability Patch

Locked

Views: 4,103

Results 1 to 2 of 2
This thread is locked. New replies are disabled.
16 Jan 2008, 11:57 AM
#1
shocker avatar

shocker

Zen Follower

Join Date:
Jul 2007
Location:
Jakarta
Posts:
346
Plugin Contributions:
0

2008 PHPMailer v1.7.2 Vunerability Patch

I'm in the process of upgrading 1.3.7 --> 1.3.8a.

I found change that I've made to **includes/classes/class.phpmailer.php

```
/
* SA 08-08-07 PHPMailer vulnerability patch (old code commented below) ***/
function SendmailSend($header, $body) {
if ($this->Sender != "") {
$sendmail = sprintf("%s -oi -f %s -t", escapeshellcmd($this->Sendmail), escapeshellarg($this->Sender));
} else {
$sendmail = sprintf("%s -oi -t", escapeshellcmd($this->Sendmail));
}

/*
function SendmailSend($header, $body) {

if ($this->Sender != "")

$sendmail = sprintf("%s -oi -f %s -t", $this->Sendmail, $this->Sender);

else

$sendmail = sprintf("%s -oi -t", $this->Sendmail);

*/


I can't tell if the fix is in the newer version. 
Please someone let me know.

s.ali
16 Jan 2008, 12:26 PM
#2
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: 2008 PHPMailer v1.7.2 Vunerability Patch

That patch was incorporated in v1.3.7.1
In v1.3.8a you'll find it around line 408 of the file.

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.