Launchpad.net

CVE 2018-16744

An issue was discovered in mgetty before 1.2.1. In fax_notify_mail() in faxrec.c, the mail_to parameter is not sanitized. It could allow for command injection if untrusted input can reach it, because popen is used.

See the CVE page on Mitre.org for more details.

References