CVE-2007-6348
Summary
| CVE | CVE-2007-6348 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-12-14 19:46:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | SquirrelMail 1.4.11 and 1.4.12, as distributed on sourceforge.net before 20071213, has been externally modified to create a Trojan Horse that introduces a PHP remote file inclusion vulnerability, which allows remote attackers to execute arbitrary code. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Squirrelmail | Squirrelmail | 1.4.11 | All | All | All |
| Application | Squirrelmail | Squirrelmail | 1.4.12 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SquirrelMail - Webmail for Nuts! | af854a3a-2127-422b-91ae-364da2661108 | www.squirrelmail.org | |
| SquirrelMail Package Compromise - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| '[SM-DEVEL] SECURITY: 1.4.12 Package Compromise' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| 'Re: [SM-DEVEL] SECURITY: 1.4.12 Package Compromise' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| 'ANNOUNCE: SquirrelMail 1.4.13 Released' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| osvdb.org/42633 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2007-12-17 | Mark J Cox | The versions of SquirrelMail packages shipped in Red Hat Enterprise Linux 3, 4, and 5 were not affected by this issue. In addition, the Red Hat Security Response Team have verified that the malicious code is not part of released Red Hat Enterprise Linux squirrelmail packages. |
There are currently no legacy QID mappings associated with this CVE.