{"id":"UBUNTU-CVE-2015-9097","details":"The mail gem before 2.5.5 for Ruby (aka A Really Ruby Mail Library) is vulnerable to SMTP command injection via CRLF sequences in a RCPT TO or MAIL FROM command, as demonstrated by CRLF sequences immediately before and after a DATA substring.","modified":"2025-07-16T07:49:10.091565Z","published":"2017-06-12T20:29:00Z","withdrawn":"2025-07-18T16:43:21Z","upstream":["CVE-2015-9097"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2015-9097"},{"type":"REPORT","url":"http://openwall.com/lists/oss-security/2015/12/11/3"},{"type":"REPORT","url":"http://www.mbsd.jp/Whitepaper/smtpi.pdf"},{"type":"REPORT","url":"https://github.com/mikel/mail/pull/1097"},{"type":"REPORT","url":"https://github.com/rubysec/ruby-advisory-db/issues/215"},{"type":"REPORT","url":"https://hackerone.com/reports/137631"},{"type":"REPORT","url":"https://rubysec.com/advisories/mail-OSVDB-131677"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2015-9097"}],"affected":[{"package":{"name":"ruby-mail","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/ruby-mail@2.6.3+dfsg1-1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.3+dfsg1-1"}]}],"versions":["2.6.1+dfsg1-2"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"2.6.3+dfsg1-1","binary_name":"ruby-mail"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2015/UBUNTU-CVE-2015-9097.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"Ubuntu","score":"medium"}]}