mirror of
https://github.com/gentoo-mirror/gentoo.git
synced 2026-08-31 21:18:09 -07:00
This leaves PHPMailer-5.2.28, which was released on 2020-03-09 and is the latest release from the 5.x series. No one has said whether or not CVE-2020-13625 affects v5.2.28 as well, but the description "insufficient output escaping" sounds scarier than it is. This bug isn't known to be exploitable; a priori it just gives the attachment the wrong name. Bug: https://bugs.gentoo.org/727584 Package-Manager: Portage-2.3.99, Repoman-2.3.22 Signed-off-by: Michael Orlitzky <mjo@gentoo.org>