SquirrelMail Variable Handling Vulnerability
BID:14254
Info
SquirrelMail Variable Handling Vulnerability
| Bugtraq ID: | 14254 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-2095 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Discovery is credited to James Bercegay of GulfTech Security. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 SuSE Linux Enterprise Server 9 SuSE Linux Desktop 1.0 SquirrelMail SquirrelMail 1.4.8 SquirrelMail SquirrelMail 1.4.4 RC1 SquirrelMail SquirrelMail 1.4.4 SquirrelMail SquirrelMail 1.4.3 RC1 SquirrelMail SquirrelMail 1.4.3 r3 SquirrelMail SquirrelMail 1.4.3 a SquirrelMail SquirrelMail 1.4.3 SquirrelMail SquirrelMail 1.4.2 SquirrelMail SquirrelMail 1.4.1 SquirrelMail SquirrelMail 1.4 RC1 SquirrelMail SquirrelMail 1.4 SquirrelMail SquirrelMail 1.2.6 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 Redhat Linux 9.0 i386 Redhat Fedora Core4 Redhat Fedora Core3 Redhat Fedora Core2 Redhat Fedora Core1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Desktop 4.0 Redhat Desktop 3.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.3.9 |
| Not Vulnerable: |
SquirrelMail SquirrelMail 1.4.5 |
Discussion
SquirrelMail Variable Handling Vulnerability
SquirrelMail is affected by an insecure variable handling vulnerability.
It was reported that an attacker can exploit this vulnerability to disclose and manipulate users' preferences, write arbitrary files in the context of 'www-data', carry out cross-site scripting and various other attacks.
Due to a lack of information, further details cannot be described at the moment. This BID will be update when more information becomes available.
SquirrelMail is affected by an insecure variable handling vulnerability.
It was reported that an attacker can exploit this vulnerability to disclose and manipulate users' preferences, write arbitrary files in the context of 'www-data', carry out cross-site scripting and various other attacks.
Due to a lack of information, further details cannot be described at the moment. This BID will be update when more information becomes available.
Exploit / POC
SquirrelMail Variable Handling Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
SquirrelMail Variable Handling Vulnerability
Solution:
Debian has released advisory DSA 756-1 to address this issue. Please see the referenced advisory for more information.
The vendor has released SquirrelMail 1.4.5 to address this issue.
A patch is available for SquirrelMail 1.4.4 from the following location:
http://www.squirrelmail.org/security/issue/2005-07-13
SUSE advisory SUSE-SR:2005:018 is available to address various issues. Please see the referenced advisory for more information.
Redhat has released security advisory RHSA-2005:595-12 addressing this issue. Please see the referenced advisory for further information.
RedHat has released a second security advisory RHSA-2005:595-15 addressing this issue for their Desktop and Enterprise Linux platforms. Please see the referenced Web advisory for further information.
Apple has released security advisory APPLE-SA-2005-08-15 addressing this and several other vulnerabilities. Please see the referenced advisory for further information.
RedHat Fedora has released security advisories FEDORA-2005-779 and FEDORA-2005-780 addressing this issue for Fedora Core 3 and Core 4. Please see the referenced advisory for further information.
RedHat Fedora has released security advisory FLSA:163047 addressing this issue. Please see the referenced advisory for further information.
Mandriva has released advisory MDKSA-2005:202 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
SquirrelMail SquirrelMail 1.2.6
SquirrelMail SquirrelMail 1.4 RC1
SquirrelMail SquirrelMail 1.4
SquirrelMail SquirrelMail 1.4.1
SquirrelMail SquirrelMail 1.4.2
SquirrelMail SquirrelMail 1.4.3 RC1
SquirrelMail SquirrelMail 1.4.3 a
SquirrelMail SquirrelMail 1.4.3 r3
SquirrelMail SquirrelMail 1.4.3
SquirrelMail SquirrelMail 1.4.4
SquirrelMail SquirrelMail 1.4.4 RC1
SquirrelMail SquirrelMail 1.4.8
Apple Mac OS X Server 10.3.9
Apple Mac OS X Server 10.4.2
MandrakeSoft Corporate Server 3.0
Solution:
Debian has released advisory DSA 756-1 to address this issue. Please see the referenced advisory for more information.
The vendor has released SquirrelMail 1.4.5 to address this issue.
A patch is available for SquirrelMail 1.4.4 from the following location:
http://www.squirrelmail.org/security/issue/2005-07-13
SUSE advisory SUSE-SR:2005:018 is available to address various issues. Please see the referenced advisory for more information.
Redhat has released security advisory RHSA-2005:595-12 addressing this issue. Please see the referenced advisory for further information.
RedHat has released a second security advisory RHSA-2005:595-15 addressing this issue for their Desktop and Enterprise Linux platforms. Please see the referenced Web advisory for further information.
Apple has released security advisory APPLE-SA-2005-08-15 addressing this and several other vulnerabilities. Please see the referenced advisory for further information.
RedHat Fedora has released security advisories FEDORA-2005-779 and FEDORA-2005-780 addressing this issue for Fedora Core 3 and Core 4. Please see the referenced advisory for further information.
RedHat Fedora has released security advisory FLSA:163047 addressing this issue. Please see the referenced advisory for further information.
Mandriva has released advisory MDKSA-2005:202 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
SquirrelMail SquirrelMail 1.2.6
-
Debian squirrelmail_1.2.6-4_all.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squirrelmail/squirrelma il_1.2.6-4_all.deb -
SquirrelMail SquirrelMail 1.4.5
s
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.4 RC1
-
SquirrelMail SquirrelMail 1.4.5
s
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.4
-
SquirrelMail SquirrelMail 1.4.5
s
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.4.1
-
SquirrelMail SquirrelMail 1.4.5
s
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.4.2
-
Mandriva squirrelmail-1.4.2-11.2.C30mdk.noarch.rpm
Corporate 3.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva squirrelmail-1.4.2-11.2.C30mdk.noarch.rpm
Corporate 3.0:
http://www1.mandrivalinux.com/en/ftp.php3 -
SquirrelMail SquirrelMail 1.4.5
s
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.4.3 RC1
-
SquirrelMail SquirrelMail 1.4.5
s
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.4.3 a
-
RedHat Fedora squirrelmail-1.4.6-0.cvs20050812.1.fc3.noarch.rpm
Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
SquirrelMail SquirrelMail 1.4.5
s
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.4.3 r3
-
SquirrelMail SquirrelMail 1.4.5
s
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.4.3
-
SquirrelMail SquirrelMail 1.4.5
s
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.4.4
-
Debian squirrelmail_1.4.4-6sarge1_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/squirrelmail/squirrelma il_1.4.4-6sarge1_all.deb -
RedHat Fedora squirrelmail-1.4.6-0.cvs20050812.1.fc4.noarch.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
SquirrelMail SquirrelMail 1.4.5
s
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.4.4 RC1
-
SquirrelMail SquirrelMail 1.4.5
s
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.4.8
-
SquirrelMail SquirrelMail 1.4.5
s
http://www.squirrelmail.org/download.php
Apple Mac OS X Server 10.3.9
-
Apple SecUpdSrvr2005-007Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=07796&plat form=osx&method=sa/SecUpdSrvr2005-007Pan.dmg
Apple Mac OS X Server 10.4.2
-
Apple SecUpdSrvr2005-007Ti.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=07795&plat form=osx&method=sa/SecUpdSrvr2005-007Ti.dmg
MandrakeSoft Corporate Server 3.0
-
Mandriva squirrelmail-1.4.5-1.1.C30mdk.noarch.rpm
Corporate 3.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva squirrelmail-1.4.5-1.1.C30mdk.noarch.rpm
Corporate 3.0:
http://www1.mandrivalinux.com/en/ftp.php3
References
SquirrelMail Variable Handling Vulnerability
References:
References:
- RHSA-2005:595-15 - Moderate: squirrelmail security update (RedHat)
- XMB Homepage (XMB)
- Patch available for CAN-2005-2095 (Jonathan Angliss
) - SquirrelMail 1.4.5 Released (Jonathan Angliss
) - SquirrelMail Arbitrary Variable Overwriting Vulnerability (GulfTech Security Research
)