=========================================================================Ubuntu Security Notice USN-4669-1
December 10, 2020

squirrelmail vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS

Summary:

SquirrelMail could be made to crash if it received specially crafted
input.

Software Description:
- squirrelmail: Webmail for nuts

Details:

It was discovered that a cross-site scripting (XSS) vulnerability in
SquirrelMail allows remote attackers to use malicious script content from
HTML e-mail to execute code and/or provoke a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
  squirrelmail                    2:1.4.23~svn20120406-2+deb8u3ubuntu0.16.04.2

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-4669-1
  CVE-2019-12970

Package Information:
  https://launchpad.net/ubuntu/+source/squirrelmail/2:1.4.23~svn20120406-2+deb8u3ubuntu0.16.04.2

Ubuntu 4669-1: SquirrelMail vulnerability

December 10, 2020
SquirrelMail could be made to crash if it received specially crafted input.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: squirrelmail 2:1.4.23~svn20120406-2+deb8u3ubuntu0.16.04.2 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4669-1

CVE-2019-12970

Severity
December 10, 2020

Package Information

https://launchpad.net/ubuntu/+source/squirrelmail/2:1.4.23~svn20120406-2+deb8u3ubuntu0.16.04.2

Related News