Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Debian: DSA-3091-2 Urgent: SquirrelMail XSS and Performance Issue Resolved

debian
Calendar Grey August 12, 2010
Debian Logo
Upgrade SquirrelMail configurations to address CSRF weaknesses and strengthen defenses against denial-of-service assaults within Debian environments.
SquirrelMail, a webmail application, does not employ a user-specific token for webforms

Summary

In addition, a denial-of-service was fixed, which could be triggered when a
passwords containing 8-bit characters was used to log in (CVE-2010-2813).

For the stable distribution (lenny), these problems have been fixed in
version 1.4.15-4+lenny3.1.

For the testing distribution (squeeze) and the unstable distribution (sid),
these problems have been fixed in version 1.4.21-1.

We recommend that you upgrade your squirrelmail packages.


Upgrade instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 5.0 alias lenny

Source archives:

Size/MD5 checksum: 34647 2251562662703a0d8e4f0de309ca60a6
Size/MD5 ...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: squirrelmail
CVE ID: CVE-2009-2964 CVE-2010-2813

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here