sup-heliotrope/sup

sup-heliotrope/sup

Releases79
Frequency2 months 3 weeks
Last Release
Stars964
A curses threads-with-tags style email client (mailing list: [email protected])

CVE History

CVEPublishedCVSS v3CVSS v2
6.8 MEDIUM

Sup before 0.13.2.1 and 0.14.x before 0.14.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of an email attachment.

6.8 MEDIUM

lib/sup/message_chunks.rb in Sup before 0.13.2.1 and 0.14.x before 0.14.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the content_type of an email attachment.