Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Gentoo: GLSA-200708-08 High: SquirrelMail Arbitrary Code Execution Risk

gentoo
Calendar Grey August 12, 2007
Dist Gentoo Esm H88
Several security flaws in SquirrelMail may allow distant attackers to run arbitrary code. All users are strongly encouraged to update promptly.
Multiple vulnerabilities have been discovered in SquirrelMail, allowing for the remote execution of arbitrary code.

Summary

Gentoo Linux Security Advisory GLSA 200708-08 https://security.gentoo.org/ Severity: High Title: SquirrelMail G/PGP plugin: Arbitrary code execution Date: August 11, 2007 Bugs: #185010 ID: 200708-08

Synopsis ======= Multiple vulnerabilities have been discovered in SquirrelMail, allowing for the remote execution of arbitrary code.
Background ========= SquirrelMail is a webmail package written in PHP. It supports IMAP and SMTP protocols.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 mail-client/squirrelmail < 1.4.10a-r2 >= 1.4.10a-r2
========== The functions deletekey(), gpg_check_sign_pgp_mime() and gpg_recv_key() used in the SquirrelMail G/PGP encryption plugin do not ...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Your message here