Lettre

Lettre

3 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 20.07.2026 15:37:58
  • Zuletzt bearbeitet 23.07.2026 17:58:34

lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug in lettre's `boring-tls` integration silently disables TLS hostname verification for callers using the default (strict) configurat...

Exploit
  • EPSS 1.49%
  • Veröffentlicht 08.08.2021 06:15:08
  • Zuletzt bearbeitet 21.11.2024 06:16:36

An issue was discovered in the lettre crate before 0.9.6 for Rust. In an e-mail message body, an attacker can place a . character after two <CR><LF> sequences and then inject arbitrary SMTP commands.

  • EPSS 1.52%
  • Veröffentlicht 12.11.2020 18:15:15
  • Zuletzt bearbeitet 21.11.2024 05:22:30

The lettre library through 0.10.0-alpha for Rust allows arbitrary sendmail option injection via transport/sendmail/mod.rs.