PHP 4.x to 4.2.2 contains a flaw that exist in the mail() function that does not properly sanitize user input. It is possible for a user may pass ASCII control characters to the mail() function that could alter the headers of email. This could result in spoofed mail headers.
Classification
Unknown or Incomplete
Technical
Arbitrary ASCII control characters may be injected into string arguments
of mail() function. If mail() arguments are taken from user's input it
may give the user ability to alter message content including mail
headers.
Solution
Upgrade to the latest version of PHP available, or disable the mail() function in the php.ini.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.