SquirrelMail G/PGP Encryption Plug-in Multiple Remote Command Execution Vulnerabilities
BID:24874
Info
SquirrelMail G/PGP Encryption Plug-in Multiple Remote Command Execution Vulnerabilities
| Bugtraq ID: | 24874 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-1924 CVE-2006-4169 CVE-2007-3778 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jul 11 2007 12:00AM |
| Updated: | Jul 05 2016 10:00PM |
| Credit: | Anonymous researchers discovered these issues. iDefense disclosed them to the public. |
| Vulnerable: |
SquirrelMail G/PGP Encryption Plugin 2.1 SquirrelMail G/PGP Encryption Plugin 2.0 Gentoo Linux |
| Not Vulnerable: | |
Discussion
SquirrelMail G/PGP Encryption Plug-in Multiple Remote Command Execution Vulnerabilities
Vulnerabilities in the SquirrelMail G/PGP encryption plugin may allow attackers to execute shell commands and PHP script code. These issues occur because the application fails to sufficiently sanitize user-supplied data.
Commands and scripts would run in the context of the webserver hosting the vulnerable software.
Three separate shell command-injection vulnerabilities and one local file-include vulnerability are present in various versions of the affected plugin. One of these issues has been addressed in G/PGP Encryption 2.1, but the others are still unfixed.
One or more of these issues may already have been documented in the following BIDs, but sufficient information is not currently available to distinguish between them:
- 24782, SquirrelMail G/PGP Encryption Plug-in Unspecified Remote Command Execution Vulnerability
- 24828, SquirrelMail G/PGP Encryption Plug-in Multiple Unspecified Remote Command Execution Vulnerabilities
All affected BIDs will be updated when more information is released.
Vulnerabilities in the SquirrelMail G/PGP encryption plugin may allow attackers to execute shell commands and PHP script code. These issues occur because the application fails to sufficiently sanitize user-supplied data.
Commands and scripts would run in the context of the webserver hosting the vulnerable software.
Three separate shell command-injection vulnerabilities and one local file-include vulnerability are present in various versions of the affected plugin. One of these issues has been addressed in G/PGP Encryption 2.1, but the others are still unfixed.
One or more of these issues may already have been documented in the following BIDs, but sufficient information is not currently available to distinguish between them:
- 24782, SquirrelMail G/PGP Encryption Plug-in Unspecified Remote Command Execution Vulnerability
- 24828, SquirrelMail G/PGP Encryption Plug-in Multiple Unspecified Remote Command Execution Vulnerabilities
All affected BIDs will be updated when more information is released.
Exploit / POC
SquirrelMail G/PGP Encryption Plug-in Multiple Remote Command Execution Vulnerabilities
Attackers may use a browser to exploit these issues.
UPDATE (December 11, 2007): An exploit of the 'deletekey()' issue is available:
Attackers may use a browser to exploit these issues.
UPDATE (December 11, 2007): An exploit of the 'deletekey()' issue is available:
Solution / Fix
SquirrelMail G/PGP Encryption Plug-in Multiple Remote Command Execution Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
NOTE: One of the command-injection issues is addressed in SquirrelMail G/PGP Encryption 2.1.
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
NOTE: One of the command-injection issues is addressed in SquirrelMail G/PGP Encryption 2.1.
References
SquirrelMail G/PGP Encryption Plug-in Multiple Remote Command Execution Vulnerabilities
References:
References:
- G/PGP Encryption Plugin (SquirrelMail)
- iDefense Security Advisory 07.11.07: SquirrelMail G/PGP Plugin deleteKey() Comma (iDefense Labs
) - iDefense Security Advisory 07.11.07: SquirrelMail G/PGP Plugin gpg_check_sign_pg (iDefense Labs
) - iDefense Security Advisory 07.11.07: SquirrelMail G/PGP Plugin gpg_help.php Loca (iDefense Labs
) - iDefense Security Advisory 07.11.07: SquirrelMail G/PGP Plugin gpg_recv_key() Co (iDefense Labs
)