CVE-2009-0030
Summary
| CVE | CVE-2009-0030 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-01-21 20:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to access other users' folder lists and configuration data in opportunistic circumstances by using the standard webmail.php interface. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3663. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Squirrelmail | Squirrelmail | 1.4.8 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat SquirrelMail Package Session Management Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Bug 480224 – Squirrelmail session management broken by security backport | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2009:004 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| SecurityTracker.com Archives - SquirrelMail on Red Hat Uses Fixed Session ID Values | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Red Hat update for squirrelmail - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Bug 480488 – CVE-2009-0030 squirrelmail: session management flaw | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.