Majordomo 1.94.3 and earlier allows remote attackers to execute arbitrary commands when the advertise or noadvertise directive is used in a configuration file, via shell metacharacters in the Reply-To header.
| Software | From | Fixed in |
|---|---|---|
| great_circle_associates / majordomo | - | 1.94.3.x |