Sup before 0.13.2.1 and 0.14.x before 0.14.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of an email attachment.
| Software | From | Fixed in |
|---|---|---|
| supmua / sup | 0.14.0 | 0.14.0.x |
| supmua / sup | 0.13.0 | 0.13.0.x |
| supmua / sup | 0.13.1 | 0.13.1.x |
| supmua / sup | 0.14.1 | 0.14.1.x |
| supmua / sup | - | 0.13.2.x |
sup
|
- | 0.13.2.1 |
sup
|
0.14.0 | 0.14.1.1 |