SquirrelMail decodeHeader HTML Injection Vulnerability
BID:11653
Info
SquirrelMail decodeHeader HTML Injection Vulnerability
| Bugtraq ID: | 11653 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-1036 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 10 2004 12:00AM |
| Updated: | Jul 12 2009 08:06AM |
| Credit: | Joost Pol disclosed this vulnerability to the vendor. |
| Vulnerable: |
SuSE Linux 8.1 SuSE Linux 8.0 i386 SuSE Linux 8.0 SquirrelMail SquirrelMail 1.5 Development Version SquirrelMail SquirrelMail 1.4.8 SquirrelMail SquirrelMail 1.4.3 RC1 SquirrelMail SquirrelMail 1.4.3 a SquirrelMail SquirrelMail 1.4.3 SquirrelMail SquirrelMail 1.4.2 SquirrelMail SquirrelMail 1.4.1 SquirrelMail SquirrelMail 1.4 SquirrelMail SquirrelMail 1.2.11 SquirrelMail SquirrelMail 1.2.10 SquirrelMail SquirrelMail 1.2.9 SquirrelMail SquirrelMail 1.2.8 SquirrelMail SquirrelMail 1.2.7 SquirrelMail SquirrelMail 1.2.6 SquirrelMail SquirrelMail 1.2.5 SquirrelMail SquirrelMail 1.2.4 SquirrelMail SquirrelMail 1.2.3 SquirrelMail SquirrelMail 1.2.2 SquirrelMail SquirrelMail 1.2.1 SquirrelMail SquirrelMail 1.2 .0 SquirrelMail SquirrelMail 1.0.5 SquirrelMail SquirrelMail 1.0.4 SGI ProPack 3.0 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 Gentoo Linux Apple Mac OS X Server 10.3.7 Apple Mac OS X Server 10.3.6 Apple Mac OS X Server 10.3.5 Apple Mac OS X Server 10.3.4 Apple Mac OS X Server 10.3.3 Apple Mac OS X Server 10.3.2 Apple Mac OS X Server 10.3.1 Apple Mac OS X Server 10.3 |
| Not Vulnerable: | |
Discussion
SquirrelMail decodeHeader HTML Injection Vulnerability
SquirrelMail is reported to be prone to an email header HTML injection vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied email header strings.
An attacker can exploit this issue to gain access to an unsuspecting user's cookie based authentication credentials; disclosure of personal email is possible. Other attacks are also possible.
SquirrelMail is reported to be prone to an email header HTML injection vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied email header strings.
An attacker can exploit this issue to gain access to an unsuspecting user's cookie based authentication credentials; disclosure of personal email is possible. Other attacks are also possible.
Exploit / POC
SquirrelMail decodeHeader HTML Injection Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
SquirrelMail decodeHeader HTML Injection Vulnerability
Solution:
The vendor has released a patch to correct this issue in version 1.4.3a of SquirrelMail. The patch may also apply to previous versions, but this has not been confirmed. A fix has been applied to CVS versions as of 23 October 2004.
SuSE Linux has released a security summary report (SUSE-SR:2005:002) that contains fixes to address this and other vulnerabilities. Customers are advised to peruse the referenced advisory for further information regarding obtaining and applying appropriate updates.
Gentoo Linux has released advisory GLSA 200411-25 dealing with this issue. Gentoo advises that all SquirrelMail users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=mail-client/squirrelmail-1.4.3a-r2"
Note: Users with the vhosts USE flag set should manually use webapp-config to finalize the update. For more information please see the referenced Gentoo advisory.
Fedora has released advisories FEDORA-2004-471 and FEDORA-2004-472 for Fedora Core 2 and 3 respectively. Please see the attached advisories for details on obtaining and applying fixes.
Conectiva Linux has made advisory CLA-2004:905 available dealing with this issue. Please see the referenced advisory for more information.
SGI has released advisory 20050101-01-U to address various issues in SGI Advanced Linux Environment 3. This advisory includes updated SGI ProPack 3 Service Pack 3 packages. Please see the referenced advisory for more information.
Apple Computers has released advisory APPLE-SA-2005-01-25 along with a security update dealing with this and other issues. Please see the referenced advisory for more information.
SquirrelMail SquirrelMail 1.2.10
SquirrelMail SquirrelMail 1.2.7
SquirrelMail SquirrelMail 1.4.1
SquirrelMail SquirrelMail 1.4.2
SquirrelMail SquirrelMail 1.4.3 a
Apple Mac OS X Server 10.3.7
SGI ProPack 3.0
Solution:
The vendor has released a patch to correct this issue in version 1.4.3a of SquirrelMail. The patch may also apply to previous versions, but this has not been confirmed. A fix has been applied to CVS versions as of 23 October 2004.
SuSE Linux has released a security summary report (SUSE-SR:2005:002) that contains fixes to address this and other vulnerabilities. Customers are advised to peruse the referenced advisory for further information regarding obtaining and applying appropriate updates.
Gentoo Linux has released advisory GLSA 200411-25 dealing with this issue. Gentoo advises that all SquirrelMail users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=mail-client/squirrelmail-1.4.3a-r2"
Note: Users with the vhosts USE flag set should manually use webapp-config to finalize the update. For more information please see the referenced Gentoo advisory.
Fedora has released advisories FEDORA-2004-471 and FEDORA-2004-472 for Fedora Core 2 and 3 respectively. Please see the attached advisories for details on obtaining and applying fixes.
Conectiva Linux has made advisory CLA-2004:905 available dealing with this issue. Please see the referenced advisory for more information.
SGI has released advisory 20050101-01-U to address various issues in SGI Advanced Linux Environment 3. This advisory includes updated SGI ProPack 3 Service Pack 3 packages. Please see the referenced advisory for more information.
Apple Computers has released advisory APPLE-SA-2005-01-25 along with a security update dealing with this and other issues. Please see the referenced advisory for more information.
SquirrelMail SquirrelMail 1.2.10
-
SuSE squirrelmail-1.2.10-189.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/squirrelmail-1.2. 10-189.i586.rpm
SquirrelMail SquirrelMail 1.2.7
-
SuSE squirrelmail-1.2.7-245.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/squirrelmail-1.2. 7-245.i586.rpm
SquirrelMail SquirrelMail 1.4.1
-
SuSE squirrelmail-1.4.1-239.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/squirrelmail-1.4. 1-239.i586.rpm -
SuSE squirrelmail-1.4.1-239.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/squirrelmail- 1.4.1-239.x86_64.rpm
SquirrelMail SquirrelMail 1.4.2
-
Fedora squirrelmail-1.4.3a-6.FC2.noarch.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
SuSE squirrelmail-1.4.2-55.4.noarch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/noarch/squirrelmail-1. 4.2-55.4.noarch.rpm -
SuSE squirrelmail-1.4.2-55.4.noarch.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/noarch/squirrelmail- 1.4.2-55.4.noarch.rpm -
SuSE squirrelmail-1.4.2-59.2.noarch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/noarch/squirrelmail-1. 4.2-59.2.noarch.rpm -
SuSE squirrelmail-1.4.2-59.2.noarch.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.2/rpm/noarch/squirrelmail- 1.4.2-59.2.noarch.rpm
SquirrelMail SquirrelMail 1.4.3 a
-
Conectiva squirrelmail-1.4.3a-13677U90_3cl.noarch.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/squirrelmail-1.4.3a-13677U9 0_3cl.noarch.rpm -
Conectiva squirrelmail-doc-1.4.3a-13677U90_3cl.noarch.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/squirrelmail-doc-1.4.3a-136 77U90_3cl.noarch.rpm -
Fedora squirrelmail-1.4.3a-6.FC3.noarch.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
SquirrelMail sm143a-xss.diff
http://prdownloads.sourceforge.net/squirrelmail/sm143a-xss.diff?downlo ad
Apple Mac OS X Server 10.3.7
-
Apple Security Update 2005-001 (Mac OS X 10.3.7 Server) 1.0
http://www.apple.com/support/downloads/securityupdate2005001macosx1037 server.html
SGI ProPack 3.0
-
SGI patch10131.tar.gz
ftp://patches.sgi.com/support/free/security/patches/ProPack/3/patch101 31.tar.gz
References
SquirrelMail decodeHeader HTML Injection Vulnerability
References:
References:
- XMB Homepage (XMB)
- [SquirrelMail Security Advisory] Cross Site Scripting in encoded text (Jonathan Angliss
) - SquirrelMail Security Advisory (Jonathan Angliss
)