Red Hat SquirrelMail Package Session Management Vulnerability
BID:33354
Info
Red Hat SquirrelMail Package Session Management Vulnerability
| Bugtraq ID: | 33354 |
| Class: | Access Validation Error |
| CVE: |
CVE-2009-0030 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 19 2009 12:00AM |
| Updated: | Feb 17 2009 11:08PM |
| Credit: | Dan Astoorian |
| Vulnerable: |
S.u.S.E. openSUSE 10.3 Redhat Squirrelmail 1.4.8-5 el4_7.2 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux 5 Server Redhat Desktop 4.0 Redhat Desktop 3.0 |
| Not Vulnerable: |
Redhat Squirrelmail 1.4.8-9 el3 Redhat Squirrelmail 1.4.8-5 el5_2.3 Redhat Squirrelmail 1.4.8-5 el4_7.3 |
Discussion
Red Hat SquirrelMail Package Session Management Vulnerability
The Red Hat 'squirrelmail' package is prone to an authentication-bypass vulnerability because of a session-handling error introduced by patches provided by Red Hat Security Advisory RHSA-2009:0010.
Attackers can exploit this issue to hijack other users' sessions and obtain sensitive information that can aid in further attacks.
The Red Hat 'squirrelmail' package is prone to an authentication-bypass vulnerability because of a session-handling error introduced by patches provided by Red Hat Security Advisory RHSA-2009:0010.
Attackers can exploit this issue to hijack other users' sessions and obtain sensitive information that can aid in further attacks.
Exploit / POC
Red Hat SquirrelMail Package Session Management Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Red Hat SquirrelMail Package Session Management Vulnerability
Solution:
The vendor has released an advisory and fixes. Please contact the vendor for details.
Solution:
The vendor has released an advisory and fixes. Please contact the vendor for details.
References
Red Hat SquirrelMail Package Session Management Vulnerability
References:
References:
- Bugzilla bug 480224 Squirrelmail session management broken by security backport (Dan Astoorian)
- Red Hat Homepage (Red Hat)