SquirrelMail G/PGP Encryption Plugin Access Validation And Input Validation Vulnerabilities
BID:26788
Info
SquirrelMail G/PGP Encryption Plugin Access Validation And Input Validation Vulnerabilities
| Bugtraq ID: | 26788 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 10 2007 12:00AM |
| Updated: | Dec 21 2007 07:21PM |
| Credit: | Tomas Kuliavas is credited with the discovery of these issues. |
| Vulnerable: |
SquirrelMail G/PGP Encryption Plugin 2.0.1 SquirrelMail G/PGP Encryption Plugin 2.1 SquirrelMail G/PGP Encryption Plugin 2.0 |
| Not Vulnerable: | |
Discussion
SquirrelMail G/PGP Encryption Plugin Access Validation And Input Validation Vulnerabilities
The G/PGP encryption plugin for SquirrelMail is prone to an input-validation vulnerability and an access-validation vulnerability.
Attackers can exploit these issues to inject arbitrary script code into public key data or to delete and overwrite arbitrary files with the privileges of the application.
SquirrelMail G/PGP Encryption Plugin 2.0, 2.0.1, and 2.1 are vulnerable; other versions may also be affected.
NOTE: One or more of these issues may already have been documented in the following BIDs, but we don't have enough information at this time to distinguish among them:
- 24782, SquirrelMail G/PGP Encryption Plug-in Unspecified Remote Command Execution Vulnerability
- 24828, SquirrelMail G/PGP Encryption Plug-in Multiple Unspecified Remote Command Execution Vulnerabilities
- 24874, SquirrelMail G/PGP Encryption Plug-in Multiple Remote Command Execution
Vulnerabilities
The G/PGP encryption plugin for SquirrelMail is prone to an input-validation vulnerability and an access-validation vulnerability.
Attackers can exploit these issues to inject arbitrary script code into public key data or to delete and overwrite arbitrary files with the privileges of the application.
SquirrelMail G/PGP Encryption Plugin 2.0, 2.0.1, and 2.1 are vulnerable; other versions may also be affected.
NOTE: One or more of these issues may already have been documented in the following BIDs, but we don't have enough information at this time to distinguish among them:
- 24782, SquirrelMail G/PGP Encryption Plug-in Unspecified Remote Command Execution Vulnerability
- 24828, SquirrelMail G/PGP Encryption Plug-in Multiple Unspecified Remote Command Execution Vulnerabilities
- 24874, SquirrelMail G/PGP Encryption Plug-in Multiple Remote Command Execution
Vulnerabilities
Exploit / POC
SquirrelMail G/PGP Encryption Plugin Access Validation And Input Validation Vulnerabilities
Attackers can exploit these issues with a browser. In the case of the input-validation vulnerability, an attacker may be able to exploit this issue through malicious JavaScript in an email or web page or by enticing an unsuspecting user to import a specially crafted public key.
The following proof of concept is available:
Attackers can exploit these issues with a browser. In the case of the input-validation vulnerability, an attacker may be able to exploit this issue through malicious JavaScript in an email or web page or by enticing an unsuspecting user to import a specially crafted public key.
The following proof of concept is available:
Solution / Fix
SquirrelMail G/PGP Encryption Plugin Access Validation And Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
SquirrelMail G/PGP Encryption Plugin Access Validation And Input Validation Vulnerabilities
References:
References:
- G/PGP Encryption Plugin (SquirrelMail)
- Two vulnerabilities in SquirrelMail GPG plugin (Tomas Kuliavas
)