SquirrelMail URL Remote Code Execution Vulnerability
BID:12413
Info
SquirrelMail URL Remote Code Execution Vulnerability
| Bugtraq ID: | 12413 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-0152 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 01 2005 12:00AM |
| Updated: | Jul 12 2009 10:06AM |
| Credit: | Grant Hollingworth is credited with the discovery of this issue. |
| Vulnerable: |
SquirrelMail SquirrelMail 1.4.8 SquirrelMail SquirrelMail 1.4.4 RC1 SquirrelMail SquirrelMail 1.4.4 SquirrelMail SquirrelMail 1.4.3 RC1 SquirrelMail SquirrelMail 1.4.3 r3 SquirrelMail SquirrelMail 1.4.3 a SquirrelMail SquirrelMail 1.4.3 SquirrelMail SquirrelMail 1.4.2 SquirrelMail SquirrelMail 1.4.1 SquirrelMail SquirrelMail 1.4 RC1 SquirrelMail SquirrelMail 1.4 SquirrelMail SquirrelMail 1.2.11 SquirrelMail SquirrelMail 1.2.10 SquirrelMail SquirrelMail 1.2.9 SquirrelMail SquirrelMail 1.2.8 SquirrelMail SquirrelMail 1.2.7 SquirrelMail SquirrelMail 1.2.6 SquirrelMail SquirrelMail 1.2.5 SquirrelMail SquirrelMail 1.2.4 SquirrelMail SquirrelMail 1.2.3 SquirrelMail SquirrelMail 1.2.2 SquirrelMail SquirrelMail 1.2.1 SquirrelMail SquirrelMail 1.2 .0 |
| Not Vulnerable: | |
Discussion
SquirrelMail URL Remote Code Execution Vulnerability
A remote code execution vulnerability affects SquirrelMail. Although unconfirmed, it is likely that this issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in functionality designed to carry out critical actions.
An attacker may leverage this issue to execute arbitrary code with the privileges of the 'www-data' user; this may facilitate privilege escalation and system compromise.
A remote code execution vulnerability affects SquirrelMail. Although unconfirmed, it is likely that this issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in functionality designed to carry out critical actions.
An attacker may leverage this issue to execute arbitrary code with the privileges of the 'www-data' user; this may facilitate privilege escalation and system compromise.
Exploit / POC
SquirrelMail URL Remote Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
SquirrelMail URL Remote Code Execution Vulnerability
Solution:
Debian has made an advisory (DSA 662-1) along with fixes available dealing with this issue. Please see the referenced advisory for more information.
Debian has released advisory DSA 662-2 to address this issue. Please see the referenced advisory for more information.
SquirrelMail SquirrelMail 1.2.6
Solution:
Debian has made an advisory (DSA 662-1) along with fixes available dealing with this issue. Please see the referenced advisory for more information.
Debian has released advisory DSA 662-2 to address this issue. Please see the referenced advisory for more information.
SquirrelMail SquirrelMail 1.2.6
-
Debian squirrelmail_1.2.6-2_all.deb
http://security.debian.org/pool/updates/main/s/squirrelmail/squirrelma il_1.2.6-2_all.deb -
Debian squirrelmail_1.2.6-3_all.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squirrelmail/squirrelma il_1.2.6-3_all.deb