SquirrelMail S/MIME Plug-in Remote Command Execution Vulnerability
BID:12467
Info
SquirrelMail S/MIME Plug-in Remote Command Execution Vulnerability
| Bugtraq ID: | 12467 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-0239 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 07 2005 12:00AM |
| Updated: | Jul 12 2009 10:06AM |
| Credit: | Discovery is credited to Karol Wiesek. |
| Vulnerable: |
SuSE Linux 8.1 SuSE Linux 8.0 i386 SuSE Linux 8.0 SuSE Linux 7.3 sparc SuSE Linux 7.3 ppc SuSE Linux 7.3 i386 SuSE Linux 7.3 SuSE Linux 7.2 i386 SuSE Linux 7.2 SuSE Linux 7.1 x86 SuSE Linux 7.1 sparc SuSE Linux 7.1 ppc SuSE Linux 7.1 alpha SuSE Linux 7.1 SuSE Linux 7.0 sparc SuSE Linux 7.0 ppc SuSE Linux 7.0 i386 SuSE Linux 7.0 alpha SuSE Linux 7.0 SuSE Linux 6.4 ppc SuSE Linux 6.4 i386 SuSE Linux 6.4 alpha SuSE Linux 6.4 SuSE Linux 6.3 ppc SuSE Linux 6.3 alpha SuSE Linux 6.3 SuSE Linux 6.2 SuSE Linux 6.1 alpha SuSE Linux 6.1 SuSE Linux 6.0 SuSE Linux 5.3 SuSE Linux 5.2 SuSE Linux 5.1 SuSE Linux 5.0 SuSE Linux 4.4.1 SuSE Linux 4.4 SuSE Linux 4.3 SuSE Linux 4.2 SuSE Linux 4.0 SuSE Linux 3.0 SuSE Linux 2.0 SuSE Linux 1.0 SquirrelMail S/MIME Plugin 0.5 SquirrelMail S/MIME Plugin 0.4 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 |
| Not Vulnerable: |
SquirrelMail S/MIME Plugin 0.6 |
Discussion
SquirrelMail S/MIME Plug-in Remote Command Execution Vulnerability
A vulnerability exists in the SquirrelMail S/MIME plug-in that may allow malicious Web mail users to execute system commands remotely. The source of the problem is that user data is passed to the PHP 'exec()' function without sufficient sanitization.
Command execution would occur in the context of the Web server hosting the vulnerable software.
A vulnerability exists in the SquirrelMail S/MIME plug-in that may allow malicious Web mail users to execute system commands remotely. The source of the problem is that user data is passed to the PHP 'exec()' function without sufficient sanitization.
Command execution would occur in the context of the Web server hosting the vulnerable software.
Exploit / POC
SquirrelMail S/MIME Plug-in Remote Command Execution Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
SquirrelMail S/MIME Plug-in Remote Command Execution Vulnerability
Solution:
This issue has been resolved in version 0.6 of the S/MIME plugin.
SuSE has released advisory SUSE-SA:2005:015 reporting in the pending vulnerabilities section that new Squirrelmail packages are available on their ftp server. Please see the referenced advisory for more information.
SUSE has released an advisory SUSE-SR:2005:008 to address various security issues affecting SUSE products. Please see the referenced advisory for more information.
SquirrelMail S/MIME Plugin 0.4
SquirrelMail S/MIME Plugin 0.5
S.u.S.E. Linux Personal 8.2
S.u.S.E. Linux Personal 9.0
S.u.S.E. Linux Personal 9.0 x86_64
S.u.S.E. Linux Personal 9.1 x86_64
S.u.S.E. Linux Personal 9.1
S.u.S.E. Linux Personal 9.2
S.u.S.E. Linux Personal 9.2 x86_64
Solution:
This issue has been resolved in version 0.6 of the S/MIME plugin.
SuSE has released advisory SUSE-SA:2005:015 reporting in the pending vulnerabilities section that new Squirrelmail packages are available on their ftp server. Please see the referenced advisory for more information.
SUSE has released an advisory SUSE-SR:2005:008 to address various security issues affecting SUSE products. Please see the referenced advisory for more information.
SquirrelMail S/MIME Plugin 0.4
-
SquirrelMail S/MIME Plugin 0.6
http://www.squirrelmail.org/plugin_view.php?id=54
SquirrelMail S/MIME Plugin 0.5
-
SquirrelMail S/MIME Plugin 0.6
http://www.squirrelmail.org/plugin_view.php?id=54
S.u.S.E. Linux Personal 8.2
-
SuSE squirrelmail-plugins-1.2.2-603.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/squirrelmail-plug ins-1.2.2-603.i586.rpm
S.u.S.E. Linux Personal 9.0
-
SuSE squirrelmail-plugins-1.4.1-289.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/squirrelmail-plug ins-1.4.1-289.i586.rpm
S.u.S.E. Linux Personal 9.0 x86_64
-
SuSE squirrelmail-plugins-1.4.1-289.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/squirrelmail- plugins-1.4.1-289.x86_64.rpm
S.u.S.E. Linux Personal 9.1 x86_64
-
SuSE squirrelmail-plugins-1.4.1-280.2.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/squirrelmail- plugins-1.4.1-280.2.x86_64.rpm
S.u.S.E. Linux Personal 9.1
-
SuSE squirrelmail-plugins-1.4.1-280.2.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/squirrelmail-plug ins-1.4.1-280.2.i586.rpm
S.u.S.E. Linux Personal 9.2
-
SuSE squirrelmail-plugins-1.4.1-286.2.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/squirrelmail-plug ins-1.4.1-286.2.i586.rpm
S.u.S.E. Linux Personal 9.2 x86_64
-
SuSE squirrelmail-plugins-1.4.1-286.2.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.2/rpm/x86_64/squirrelmail- plugins-1.4.1-286.2.x86_64.rpm
References
SquirrelMail S/MIME Plug-in Remote Command Execution Vulnerability
References:
References:
- S/MIME Plugin Homepage (SquirrelMail)
- SquirrelMail S/MIME Plugin Command Injection Vulnerability (iDEFENSE)