SquirrelMail Variable Handling Vulnerability

Solution:
Debian has released advisory DSA 756-1 to address this issue. Please see the referenced advisory for more information.

The vendor has released SquirrelMail 1.4.5 to address this issue.

A patch is available for SquirrelMail 1.4.4 from the following location:

http://www.squirrelmail.org/security/issue/2005-07-13

SUSE advisory SUSE-SR:2005:018 is available to address various issues. Please see the referenced advisory for more information.

Redhat has released security advisory RHSA-2005:595-12 addressing this issue. Please see the referenced advisory for further information.

RedHat has released a second security advisory RHSA-2005:595-15 addressing this issue for their Desktop and Enterprise Linux platforms. Please see the referenced Web advisory for further information.

Apple has released security advisory APPLE-SA-2005-08-15 addressing this and several other vulnerabilities. Please see the referenced advisory for further information.

RedHat Fedora has released security advisories FEDORA-2005-779 and FEDORA-2005-780 addressing this issue for Fedora Core 3 and Core 4. Please see the referenced advisory for further information.

RedHat Fedora has released security advisory FLSA:163047 addressing this issue. Please see the referenced advisory for further information.

Mandriva has released advisory MDKSA-2005:202 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.


SquirrelMail SquirrelMail 1.2.6

SquirrelMail SquirrelMail 1.4 RC1

SquirrelMail SquirrelMail 1.4

SquirrelMail SquirrelMail 1.4.1

SquirrelMail SquirrelMail 1.4.2

SquirrelMail SquirrelMail 1.4.3 RC1

SquirrelMail SquirrelMail 1.4.3 a

SquirrelMail SquirrelMail 1.4.3 r3

SquirrelMail SquirrelMail 1.4.3

SquirrelMail SquirrelMail 1.4.4

SquirrelMail SquirrelMail 1.4.4 RC1

SquirrelMail SquirrelMail 1.4.8

Apple Mac OS X Server 10.3.9

Apple Mac OS X Server 10.4.2

MandrakeSoft Corporate Server 3.0


 

Privacy Statement
Copyright 2010, SecurityFocus