Download Latest Version 6.2.0 source code.tar.gz (27.0 kB)
Email in envelope

Get an email when there's a new version of IMAP Library for Laravel

Home / 5.3.0
Name Modified Size InfoDownloads / Week
Parent folder
5.3.0 - Security patch source code.tar.gz 2023-06-20 25.3 kB
5.3.0 - Security patch source code.zip 2023-06-20 37.1 kB
README.md 2023-06-20 1.2 kB
Totals: 3 Items   63.5 kB 0

Fixed

Security Impact and Mitigation

Impacted are all versions below v5.3.0. If possible, update to >= v5.3.0 as soon as possible. Impacted was the Attachment::save method which could be used to write files to the local filesystem. The path was not properly sanitized and could be used to write files to arbitrary locations.

However, the Attachment::save method is not used by default and has to be called manually. If you are using this method without providing a sanitized path, you are affected by this vulnerability. If you are not using this method or are providing a sanitized path, you are not affected by this vulnerability and no immediate action is required.

If you have any questions, please feel welcome to join this issue: https://github.com/Webklex/php-imap/issues/416

Timeline

Source: README.md, updated 2023-06-20