SquirrelMail G/PGP Encryption Plug-in Unspecified Remote Command Execution Vulnerability
BID:24782
Info
SquirrelMail G/PGP Encryption Plug-in Unspecified Remote Command Execution Vulnerability
| Bugtraq ID: | 24782 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3634 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 02 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | This vulnerability was reported by WabiSabiLabi. The researcher responsible for discovering this issue is not known. |
| Vulnerable: |
SquirrelMail G/PGP Encryption Plugin 2.0 |
| Not Vulnerable: |
SquirrelMail G/PGP Encryption Plugin 2.1 |
Discussion
SquirrelMail G/PGP Encryption Plug-in Unspecified Remote Command Execution Vulnerability
A vulnerability in the SquirrelMail G/PGP encryption plugin may allow malicious webmail users to execute system commands remotely. The issue occurs because the application fails to sufficiently sanitize user data.
Commands would run in the context of the webserver hosting the vulnerable software. This issue may be exploited by sending email to a user utilizing the affected plugin. When the plugin attempts to process the email, the malicious code will be executed, making successful exploits easier for attackers to attempt.
Reports indicate that this issue has been tested with SquirrelMail 1.4.10a and G/PGP Plugin 2.0. Other versions may be affected as well.
A vulnerability in the SquirrelMail G/PGP encryption plugin may allow malicious webmail users to execute system commands remotely. The issue occurs because the application fails to sufficiently sanitize user data.
Commands would run in the context of the webserver hosting the vulnerable software. This issue may be exploited by sending email to a user utilizing the affected plugin. When the plugin attempts to process the email, the malicious code will be executed, making successful exploits easier for attackers to attempt.
Reports indicate that this issue has been tested with SquirrelMail 1.4.10a and G/PGP Plugin 2.0. Other versions may be affected as well.
Exploit / POC
SquirrelMail G/PGP Encryption Plug-in Unspecified Remote Command Execution Vulnerability
An exploit is not required.
A proof of concept has been developed but is not publicly available.
An exploit is not required.
A proof of concept has been developed but is not publicly available.
Solution / Fix
SquirrelMail G/PGP Encryption Plug-in Unspecified Remote Command Execution Vulnerability
Solution:
The vendor has released SquirrelMail 2.1 to address this issue. Please see the references for more information.
SquirrelMail G/PGP Encryption Plugin 2.0
Solution:
The vendor has released SquirrelMail 2.1 to address this issue. Please see the references for more information.
SquirrelMail G/PGP Encryption Plugin 2.0
-
SquirrelMail G/PGP Encryption Plugin version 2.1
http://www.squirrelmail.org/plugin_download.php?id=153&rev=1303
References
SquirrelMail G/PGP Encryption Plug-in Unspecified Remote Command Execution Vulnerability
References:
References:
- [VIM] SquirrelMail GPG Plugin Vulnerabilities (George A. Theall)
- G/PGP Encryption Plugin (SquirrelMail)
- Re: [Dailydave] SquirrelMail GPG Plugin vuln (Nicob)
- Re: [VIM] SquirrelMail GPG Plugin Vulnerabilities (Nicob
) - ZD-00000004 - Squirrelmail GPG Plugin Command Execution (WabiSabiLabi)