|
Family: Red Hat Local Security Checks --> Category: infos
RHSA-2005-595: squirrelmail Vulnerability Scan
Vulnerability Scan Summary Check for the version of the squirrelmail packages
Detailed Explanation for this Vulnerability Test
An updated squirrelmail package that fixes two security issues is now
available.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
SquirrelMail is a standards-based webmail package written in PHP4.
A bug was found in the way SquirrelMail handled the $_POST variable. A
user's SquirrelMail preferences could be read or modified if the user is
tricked into visiting a malicious URL. The Common Vulnerabilities and
Exposures project assigned the name CVE-2005-2095 to this issue.
Several cross-site scripting bugs were discovered in SquirrelMail. An
attacker could inject arbitrary Javascript or HTML content into
SquirrelMail pages by tricking a user into visiting a carefully crafted
URL, or by sending them a carefully constructed HTML email message.
(CVE-2005-1769)
All users of SquirrelMail should upgrade to this updated package, which
contains backported patches that resolve these issues.
Solution : http://rhn.redhat.com/errata/RHSA-2005-595.html
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|