SquirrelMail SquirrelSpell Remote Shell Command Execution Vulnerability
BID:3952
Info
SquirrelMail SquirrelSpell Remote Shell Command Execution Vulnerability
| Bugtraq ID: | 3952 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 24 2002 12:00AM |
| Updated: | Jan 24 2002 12:00AM |
| Credit: | Posted to the BugTraq mailing list by <[email protected]>. |
| Vulnerable: |
SquirrelMail SquirrelSpell 0.3.5 |
| Not Vulnerable: |
SquirrelMail SquirrelSpell 0.3.8 SquirrelMail SquirrelSpell 0.3.7 SquirrelMail SquirrelSpell 0.3.6 |
Discussion
SquirrelMail SquirrelSpell Remote Shell Command Execution Vulnerability
SquirrelMail is a feature rich webmail program implemented in the PHP4 language. It is available for Linux and Unix based operating systems. SquirrelMail allows for extended functionality through a plugin system.
The SquirrelSpell plugin for SquirrelMail may, if called directly, pass user supplied input to a shell command. If the input contains shell metacharacters, arbitary commands may be executed. Exploitation of this vulnerability may lead to local access as the non-privileged user 'nobody'.
Earlier versions of SquirrelSpell may share this vulnerability.
SquirrelMail is a feature rich webmail program implemented in the PHP4 language. It is available for Linux and Unix based operating systems. SquirrelMail allows for extended functionality through a plugin system.
The SquirrelSpell plugin for SquirrelMail may, if called directly, pass user supplied input to a shell command. If the input contains shell metacharacters, arbitary commands may be executed. Exploitation of this vulnerability may lead to local access as the non-privileged user 'nobody'.
Earlier versions of SquirrelSpell may share this vulnerability.
Exploit / POC
SquirrelMail SquirrelSpell Remote Shell Command Execution Vulnerability
No exploit code is required to take advantage of this issue.
No exploit code is required to take advantage of this issue.
Solution / Fix
SquirrelMail SquirrelSpell Remote Shell Command Execution Vulnerability
Solution:
The author of SquirrelSpell has released a patch.
Additionally, this issue was addressed in version 0.3.6 of SquirrelSpell, which ships with SquirrelMail 1.2.4. A number of other issues have been addressed in more recent versions of SquirrelSpell and SquirrelMail. Users are advised to upgrade.
SquirrelMail SquirrelSpell 0.3.5
Solution:
The author of SquirrelSpell has released a patch.
Additionally, this issue was addressed in version 0.3.6 of SquirrelSpell, which ships with SquirrelMail 1.2.4. A number of other issues have been addressed in more recent versions of SquirrelSpell and SquirrelMail. Users are advised to upgrade.
SquirrelMail SquirrelSpell 0.3.5
-
Konstantin Riabitsev security_fix.sh
http://www.dulug.duke.edu/~icon/misc/security_fix.sh.txt -
SquirrelMail squirrelmail-1.2.6
http://www.squirrelmail.org/download.php
References
SquirrelMail SquirrelSpell Remote Shell Command Execution Vulnerability
References:
References:
- XMB Homepage (XMB)