Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 7: MGASA-2021-0010 Moderate: SquirrelMail XSS Attack Risk

mageia
Calendar Grey January 8, 2021
Dist Mageia Esm H88
Vulnerable code execution in SquirrelMail caused by input validation error. Patch available to address discovered security vulnerabilities promptly.
XSS was discovered in SquirrelMail through 1.4.22

Summary

XSS was discovered in SquirrelMail through 1.4.22. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. Malicious script content from HTML e-mail can be executed within the application context via crafted use of (for example) a NOEMBED, NOFRAMES, NOSCRIPT, or TEXTAREA element ().
An unsafe use of unserialize() in compose.php has also been fixed.

References

- https://bugs.mageia.org/show_bug.cgi?id=27821

- https://www.openwall.com/lists/oss-security/2020/06/20/1

- https://ubuntu.com/security/notices/USN-4669-1

- https://www.cve.org/CVERecord?id=CVE-2019-12970

Resolution

SRPMS

- 7/core/squirrelmail-1.4.23-0.svn20201220_0200.1.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 08 Jan 2021
URL: https://advisories.mageia.org/MGASA-2021-0010.html
Type: security
CVE: CVE-2019-12970

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here