CVE-2008-5619
Publication date 17 December 2008
Last updated 24 July 2024
Ubuntu priority
Description
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attackers to execute arbitrary code via crafted input that is processed by the preg_replace function with the eval switch.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| moodle | ||
| roundcube | ||
Notes
mdeslaur
moodle recently copied roundcube's html2text due to their copy being non-free (1.8.2.dfsg-1)
Patch details
| Package | Patch details |
|---|---|
| roundcube |
References
Related Ubuntu Security Notices (USN)
- USN-791-1
- Moodle vulnerabilities
- 24 June 2009