SquirrelMail Variable Handling Vulnerability

BID:14254

Info

SquirrelMail Variable Handling Vulnerability

Bugtraq ID: 14254
Class: Input Validation Error
CVE: CVE-2005-2095
Remote: Yes
Local: No
Published: Jul 13 2005 12:00AM
Updated: Jul 12 2009 04:06PM
Credit: Discovery is credited to James Bercegay of GulfTech Security.
Vulnerable: SuSE SUSE Linux Enterprise Server 8
+ Linux kernel 2.4.21
+ Linux kernel 2.4.19
SuSE Linux Enterprise Server 9
SuSE Linux Desktop 1.0
SquirrelMail SquirrelMail 1.4.8
SquirrelMail SquirrelMail 1.4.4 RC1
SquirrelMail SquirrelMail 1.4.4
+ Debian Linux 3.1 sparc
+ Debian Linux 3.1 s/390
+ Debian Linux 3.1 s/390
+ Debian Linux 3.1 s/390
+ Debian Linux 3.1 ppc
+ Debian Linux 3.1 ppc
+ Debian Linux 3.1 ppc
+ Debian Linux 3.1 mipsel
+ Debian Linux 3.1 mipsel
+ Debian Linux 3.1 mipsel
+ Debian Linux 3.1 mips
+ Debian Linux 3.1 mips
+ Debian Linux 3.1 mips
+ Debian Linux 3.1 m68k
+ Debian Linux 3.1 m68k
+ Debian Linux 3.1 m68k
+ Debian Linux 3.1 ia-64
+ Debian Linux 3.1 ia-64
+ Debian Linux 3.1 ia-64
+ Debian Linux 3.1 ia-32
+ Debian Linux 3.1 ia-32
+ Debian Linux 3.1 ia-32
+ Debian Linux 3.1 hppa
+ Debian Linux 3.1 hppa
+ Debian Linux 3.1 hppa
+ Debian Linux 3.1 arm
+ Debian Linux 3.1 arm
+ Debian Linux 3.1 arm
+ Debian Linux 3.1 alpha
+ Debian Linux 3.1 alpha
+ Debian Linux 3.1 alpha
+ Debian Linux 3.1
+ Debian Linux 3.1
+ Debian Linux 3.1
+ Gentoo Linux
+ Gentoo Linux
+ Gentoo Linux
SquirrelMail SquirrelMail 1.4.3 RC1
SquirrelMail SquirrelMail 1.4.3 r3
+ Gentoo Linux
SquirrelMail SquirrelMail 1.4.3 a
+ Redhat Fedora Core3
+ Redhat Fedora Core3
+ Redhat Fedora Core3
+ Redhat Fedora Core2
+ Redhat Fedora Core2
SquirrelMail SquirrelMail 1.4.3
SquirrelMail SquirrelMail 1.4.2
+ MandrakeSoft Corporate Server 3.0 x86_64
+ MandrakeSoft Corporate Server 3.0
+ MandrakeSoft Corporate Server 3.0
+ MandrakeSoft Corporate Server 3.0
+ Redhat Fedora Core2
+ Redhat Fedora Core2
+ Redhat Fedora Core2
SquirrelMail SquirrelMail 1.4.1
SquirrelMail SquirrelMail 1.4 RC1
SquirrelMail SquirrelMail 1.4
SquirrelMail SquirrelMail 1.2.6
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0
+ Debian Linux 3.0
S.u.S.E. SuSE Linux School Server for i386
S.u.S.E. SUSE LINUX Retail Solution 8.0
S.u.S.E. SuSE Linux Openexchange Server 4.0
S.u.S.E. Open-Enterprise-Server 9.0
S.u.S.E. Novell Linux Desktop 9.0
S.u.S.E. Linux Professional 9.3 x86_64
S.u.S.E. Linux Professional 9.3
S.u.S.E. Linux Professional 9.2 x86_64
S.u.S.E. Linux Professional 9.2
S.u.S.E. Linux Professional 9.1 x86_64
S.u.S.E. Linux Professional 9.1
S.u.S.E. Linux Professional 9.0 x86_64
S.u.S.E. Linux Professional 9.0
S.u.S.E. Linux Professional 8.2
S.u.S.E. Linux Personal 9.3 x86_64
S.u.S.E. Linux Personal 9.3
S.u.S.E. Linux Personal 9.2 x86_64
S.u.S.E. Linux Personal 9.2
S.u.S.E. Linux Personal 9.1 x86_64
S.u.S.E. Linux Personal 9.1
S.u.S.E. Linux Personal 9.0 x86_64
S.u.S.E. Linux Personal 9.0
S.u.S.E. Linux Personal 8.2
Redhat Linux 9.0 i386
Redhat Fedora Core4
Redhat Fedora Core3
Redhat Fedora Core2
Redhat Fedora Core1
Redhat Enterprise Linux WS 4
Redhat Enterprise Linux WS 3
Redhat Enterprise Linux ES 4
Redhat Enterprise Linux ES 3
Redhat Enterprise Linux AS 4
Redhat Enterprise Linux AS 3
Redhat Desktop 4.0
Redhat Desktop 3.0
MandrakeSoft Corporate Server 3.0 x86_64
MandrakeSoft Corporate Server 3.0
Apple Mac OS X Server 10.4.2
Apple Mac OS X Server 10.3.9
Not Vulnerable: SquirrelMail SquirrelMail 1.4.5
+ MandrakeSoft Corporate Server 3.0 x86_64
+ MandrakeSoft Corporate Server 3.0
+ MandrakeSoft Corporate Server 3.0
+ MandrakeSoft Corporate Server 3.0

Discussion

SquirrelMail Variable Handling Vulnerability

SquirrelMail is affected by an insecure variable handling vulnerability.

It was reported that an attacker can exploit this vulnerability to disclose and manipulate users' preferences, write arbitrary files in the context of 'www-data', carry out cross-site scripting and various other attacks.

Due to a lack of information, further details cannot be described at the moment. This BID will be update when more information becomes available.

Exploit / POC

SquirrelMail Variable Handling Vulnerability

An exploit is not required.

Solution / Fix

SquirrelMail Variable Handling Vulnerability

Solution:
Debian has released advisory DSA 756-1 to address this issue. Please see the referenced advisory for more information.

The vendor has released SquirrelMail 1.4.5 to address this issue.

A patch is available for SquirrelMail 1.4.4 from the following location:

http://www.squirrelmail.org/security/issue/2005-07-13

SUSE advisory SUSE-SR:2005:018 is available to address various issues. Please see the referenced advisory for more information.

Redhat has released security advisory RHSA-2005:595-12 addressing this issue. Please see the referenced advisory for further information.

RedHat has released a second security advisory RHSA-2005:595-15 addressing this issue for their Desktop and Enterprise Linux platforms. Please see the referenced Web advisory for further information.

Apple has released security advisory APPLE-SA-2005-08-15 addressing this and several other vulnerabilities. Please see the referenced advisory for further information.

RedHat Fedora has released security advisories FEDORA-2005-779 and FEDORA-2005-780 addressing this issue for Fedora Core 3 and Core 4. Please see the referenced advisory for further information.

RedHat Fedora has released security advisory FLSA:163047 addressing this issue. Please see the referenced advisory for further information.

Mandriva has released advisory MDKSA-2005:202 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.


SquirrelMail SquirrelMail 1.2.6

SquirrelMail SquirrelMail 1.4 RC1

SquirrelMail SquirrelMail 1.4

SquirrelMail SquirrelMail 1.4.1

SquirrelMail SquirrelMail 1.4.2

SquirrelMail SquirrelMail 1.4.3 RC1

SquirrelMail SquirrelMail 1.4.3 a

SquirrelMail SquirrelMail 1.4.3 r3

SquirrelMail SquirrelMail 1.4.3

SquirrelMail SquirrelMail 1.4.4

SquirrelMail SquirrelMail 1.4.4 RC1

SquirrelMail SquirrelMail 1.4.8

Apple Mac OS X Server 10.3.9

Apple Mac OS X Server 10.4.2

MandrakeSoft Corporate Server 3.0

References

SquirrelMail Variable Handling Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report