The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
https://www.drupal.org/psa-2016-004
https://github.com/PHPMailer/PHPMailer/releases/tag/v5.2.18
https://developer.joomla.org/security-centre/668-20161205-phpmailer-security-advisory.html