Executive brief
Metamail is a utility used by email clients to handle multimedia messages and various attachments. A vulnerability in how it processes email headers allows an attacker to send a specially crafted message that executes unauthorized commands on the recipient's computer. This could lead to a complete system takeover or the theft of sensitive personal data if a user opens the malicious email.
Technical details
A command injection vulnerability exists in the metamail package due to improper sanitization of message headers. When metamail is invoked to process an incoming email, an attacker can leverage specially crafted header fields to execute arbitrary shell commands with the privileges of the user running the mail reader. This is a remote attack vector requiring the victim to open or process the malicious message. The vulnerability is triggered during the parsing phase of MIME-compliant messages. Users are advised to update to patched versions of metamail or transition to modern MIME handling utilities.
Affected products
- Bellcore metamail
Timeline
- 1997-05-21: disclosed: Initial publication date in NVD