SquirrelMail Multiple Unspecified Cross-Site Scripting Vulnerabilities
BID:13973
Info
SquirrelMail Multiple Unspecified Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 13973 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-1769 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 16 2005 12:00AM |
| Updated: | Mar 19 2015 08:33AM |
| Credit: | This vulnerability was reported by the vendor. |
| Vulnerable: |
WackoWiki WackoWiki R3 WackoWiki WackoWiki R2 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE Linux Desktop 1.0 SquirrelMail SquirrelMail 1.4.8 SquirrelMail SquirrelMail 1.4.4 SquirrelMail SquirrelMail 1.4.3 RC1 SquirrelMail SquirrelMail 1.4.3 r3 SquirrelMail SquirrelMail 1.4.3 a SquirrelMail SquirrelMail 1.4.3 SquirrelMail SquirrelMail 1.4.2 SquirrelMail SquirrelMail 1.4.1 SquirrelMail SquirrelMail 1.4 RC1 SquirrelMail SquirrelMail 1.4 SquirrelMail SquirrelMail 1.2.6 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 Redhat Linux 9.0 i386 Redhat Fedora Core4 Redhat Fedora Core3 Redhat Fedora Core2 Redhat Fedora Core1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 Gentoo Linux Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.3.9 |
| Not Vulnerable: |
WackoWiki WackoWiki R3.5 SquirrelMail SquirrelMail 1.4.5 SquirrelMail SquirrelMail 1.4.4 |
Discussion
SquirrelMail Multiple Unspecified Cross-Site Scripting Vulnerabilities
SquirrelMail is affected by multiple unspecified cross-site scripting vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied URI input.
These issues could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.
SquirrelMail is affected by multiple unspecified cross-site scripting vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied URI input.
These issues could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.
Exploit / POC
SquirrelMail Multiple Unspecified Cross-Site Scripting Vulnerabilities
No exploit is required.
No exploit is required.
Solution / Fix
SquirrelMail Multiple Unspecified Cross-Site Scripting Vulnerabilities
Solution:
The vendor has addressed this issue with a patch.
Gentoo Linux has released advisory GLSA 200506-19 addressing this issue. Gentoo recommends all SquirrelMail users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=mail-client/squirrelmail-1.4.4"
Note: Users with the vhosts USE flag set should manually use webapp-config to finalize the update.
Mandriva Linux has released advisory MDKSA-2005:108 addressing this issue. Please see the referenced advisory for further information.
Debian has released advisory DSA 756-1 to address these issues. Please see the referenced advisory for more information.
The vendor has released SquirrelMail 1.4.5 to address these issues.
SUSE advisory SUSE-SR:2005:018 is available to address various issues. Please see the referenced advisory for more information.
RedHat has released security advisory RHSA-2005:595-12 addressing this issue. Please see the referenced advisory for further information.
RedHat has released security advisory RHSA-2005:595-15 addressing this issue for their Desktop and Enterprise Linux platforms. Please see the referenced Web advisory for further information.
Apple has released security advisory APPLE-SA-2005-08-15 addressing this and several other vulnerabilities. Please see the referenced advisory for further information.
RedHat Fedora has released security advisories FEDORA-2005-779 and FEDORA-2005-780 addressing this issue for Fedora Core 3 and Core 4. Please see the referenced advisory for further information.
RedHat Fedora has released Fedora Legacy Update Advisory FLSA:163047 addressing this issue. Please see the referenced advisory for further information.
WackoWiki WackoWiki R3
WackoWiki WackoWiki R2
SquirrelMail SquirrelMail 1.2.6
SquirrelMail SquirrelMail 1.4 RC1
SquirrelMail SquirrelMail 1.4
SquirrelMail SquirrelMail 1.4.1
SquirrelMail SquirrelMail 1.4.2
SquirrelMail SquirrelMail 1.4.3 RC1
SquirrelMail SquirrelMail 1.4.3 a
SquirrelMail SquirrelMail 1.4.3 r3
SquirrelMail SquirrelMail 1.4.3
SquirrelMail SquirrelMail 1.4.4
SquirrelMail SquirrelMail 1.4.8
Apple Mac OS X Server 10.3.9
Apple Mac OS X Server 10.4.2
Solution:
The vendor has addressed this issue with a patch.
Gentoo Linux has released advisory GLSA 200506-19 addressing this issue. Gentoo recommends all SquirrelMail users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=mail-client/squirrelmail-1.4.4"
Note: Users with the vhosts USE flag set should manually use webapp-config to finalize the update.
Mandriva Linux has released advisory MDKSA-2005:108 addressing this issue. Please see the referenced advisory for further information.
Debian has released advisory DSA 756-1 to address these issues. Please see the referenced advisory for more information.
The vendor has released SquirrelMail 1.4.5 to address these issues.
SUSE advisory SUSE-SR:2005:018 is available to address various issues. Please see the referenced advisory for more information.
RedHat has released security advisory RHSA-2005:595-12 addressing this issue. Please see the referenced advisory for further information.
RedHat has released security advisory RHSA-2005:595-15 addressing this issue for their Desktop and Enterprise Linux platforms. Please see the referenced Web advisory for further information.
Apple has released security advisory APPLE-SA-2005-08-15 addressing this and several other vulnerabilities. Please see the referenced advisory for further information.
RedHat Fedora has released security advisories FEDORA-2005-779 and FEDORA-2005-780 addressing this issue for Fedora Core 3 and Core 4. Please see the referenced advisory for further information.
RedHat Fedora has released Fedora Legacy Update Advisory FLSA:163047 addressing this issue. Please see the referenced advisory for further information.
WackoWiki WackoWiki R3
-
WackoWiki WackoWiki R4
http://wackowiki.com/WackoDownload/InEnglish
WackoWiki WackoWiki R2
-
WackoWiki WackoWiki R4
http://wackowiki.com/WackoDownload/InEnglish
SquirrelMail SquirrelMail 1.2.6
-
Debian squirrelmail_1.2.6-4_all.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squirrelmail/squirrelma il_1.2.6-4_all.deb -
SquirrelMail SquirrelMail 1.4.5
s
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.4 RC1
-
SquirrelMail sqm-144-xss.patch
http://prdownloads.sourceforge.net/squirrelmail/sqm-144-xss.patch?down load -
SquirrelMail SquirrelMail 1.4.5
s
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.4
-
SquirrelMail sqm-144-xss.patch
http://prdownloads.sourceforge.net/squirrelmail/sqm-144-xss.patch?down load -
SquirrelMail SquirrelMail 1.4.5
s
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.4.1
-
SquirrelMail sqm-144-xss.patch
http://prdownloads.sourceforge.net/squirrelmail/sqm-144-xss.patch?down load -
SquirrelMail SquirrelMail 1.4.5
s
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.4.2
-
SquirrelMail sqm-144-xss.patch
http://prdownloads.sourceforge.net/squirrelmail/sqm-144-xss.patch?down load -
SquirrelMail SquirrelMail 1.4.5
s
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.4.3 RC1
-
SquirrelMail sqm-144-xss.patch
http://prdownloads.sourceforge.net/squirrelmail/sqm-144-xss.patch?down load -
SquirrelMail SquirrelMail 1.4.5
s
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.4.3 a
-
RedHat Fedora squirrelmail-1.4.6-0.cvs20050812.1.fc3.noarch.rpm
Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
SquirrelMail sqm-144-xss.patch
http://prdownloads.sourceforge.net/squirrelmail/sqm-144-xss.patch?down load -
SquirrelMail SquirrelMail 1.4.5
s
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.4.3 r3
-
SquirrelMail sqm-144-xss.patch
http://prdownloads.sourceforge.net/squirrelmail/sqm-144-xss.patch?down load -
SquirrelMail SquirrelMail 1.4.5
s
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.4.3
-
SquirrelMail sqm-144-xss.patch
http://prdownloads.sourceforge.net/squirrelmail/sqm-144-xss.patch?down load -
SquirrelMail SquirrelMail 1.4.5
s
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.4.4
-
Debian squirrelmail_1.4.4-6sarge1_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/squirrelmail/squirrelma il_1.4.4-6sarge1_all.deb -
RedHat Fedora squirrelmail-1.4.6-0.cvs20050812.1.fc4.noarch.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
SquirrelMail sqm-144-xss.patch
http://prdownloads.sourceforge.net/squirrelmail/sqm-144-xss.patch?down load -
SquirrelMail SquirrelMail 1.4.5
s
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.4.8
-
SquirrelMail sqm-144-xss.patch
http://prdownloads.sourceforge.net/squirrelmail/sqm-144-xss.patch?down load -
SquirrelMail SquirrelMail 1.4.5
s
http://www.squirrelmail.org/download.php
Apple Mac OS X Server 10.3.9
-
Apple SecUpdSrvr2005-007Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=07796&plat form=osx&method=sa/SecUpdSrvr2005-007Pan.dmg
Apple Mac OS X Server 10.4.2
-
Apple SecUpdSrvr2005-007Ti.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=07795&plat form=osx&method=sa/SecUpdSrvr2005-007Ti.dmg
References
SquirrelMail Multiple Unspecified Cross-Site Scripting Vulnerabilities
References:
References:
- RHSA-2005:595-15 - Moderate: squirrelmail security update (RedHat)
- Several cross site scripting vulnerabilities (SquirrelMail)
- WackoWiki Release Notes (WackoWiki)
- XMB Homepage (XMB)
- [SM-ANNOUNCE] Patch fixes SquirrelMail cross site scripting vulnerabilities [CAN (Jonathan Angliss
) - SquirrelMail 1.4.5 Released (Jonathan Angliss
)