CVE-2025-59689
Description
Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7.
Summary dbcve.org
Libraesva Email Security Gateway versions 4.5 through 5.5.x before 5.5.7 contains a command injection vulnerability in the compressed email attachment processing function. An attacker can execute arbitrary OS commands by embedding malicious payloads within compressed attachments (such as zip, tar, or gz files) that the gateway unpacks and processes without proper input sanitization.
Mitigation
Upgrade Libraesva ESG to version 5.0.31, 5.1.20, 5.2.31, 5.4.8, or 5.5.7 (or later) to patch the command injection vulnerability. As a temporary mitigation, consider filtering or quarantining compressed attachments at the MTA layer until the upgrade can be completed.