Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
XSS was discovered in SquirrelMail through 1.4.22. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. Malicious script content from HTML e-mail can be executed within the application context via crafted use of (for example) a NOEMBED, NOFRAMES, NOSCRIPT, or TEXTAREA element (). . MGASA-2021-0010 - Updated squirrelmail packages fix security vulnerabilities Publication date: 08 Jan 2021 URL: https://advisories.mageia.org/MGASA-2021-0010.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-12970 XSS was discovered in SquirrelMail through 1.4.22. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. Malicious script content from HTML e-mail can be executed within the application context via crafted use of (for example) a NOEMBED, NOFRAMES, NOSCRIPT, or TEXTAREA element (). An unsafe use of unserialize() in compose.php has also been fixed. References: - https://bugs.mageia.org/show_bug.cgi?id=27821 - https://www.openwall.com/lists/oss-security/2020/06/20/1 - https://ubuntu.com/security/notices/USN-4669-1 - https://www.cve.org/CVERecord?id=CVE-2019-12970 SRPMS: - 7/core/squirrelmail-1.4.23-0.svn20201220_0200.1.mga7 . Vulnerable code execution in SquirrelMail caused by input validation error. Patch available to address discovered security vulnerabilities promptly.. SquirrelMail Security,Mageia XSS,Mageia Security Patch,SquirrelMail Update,XSS Attack Prevention. . Severity: Important. LinuxSecurity.com Team
SquirrelMail could be made to crash if it received specially crafted input.. =========================================================================Ubuntu Security Notice USN-4669-1 December 10, 2020 squirrelmail vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: SquirrelMail could be made to crash if it received specially crafted input. Software Description: - squirrelmail: Webmail for nuts Details: It was discovered that a cross-site scripting (XSS) vulnerability in SquirrelMail allows remote attackers to use malicious script content from HTML e-mail to execute code and/or provoke a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: squirrelmail 2:1.4.23~svn20120406-2+deb8u3ubuntu0.16.04.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4669-1 CVE-2019-12970 Package Information: https://launchpad.net/ubuntu/+source/squirrelmail/2:1.4.23~svn20120406-2+deb8u3ubuntu0.16.04.2 . PigeonMail on Ubuntu 20.04 LTS is vulnerable to failures from malicious inputs resulting in CSRF vulnerabilities.. SquirrelMail Update, XSS Vulnerability, Remote Code Execution, Denial of Service, Ubuntu Security. . LinuxSecurity.com Team
updated to 1.4 branch snapshot containing several security fixes. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-ad02f64a79 2019-08-15 18:07:56.659694 --------------------------------------------------------------------------------Name : squirrelmail Product : Fedora 30 Version : 1.4.23 Release : 1.fc30.20190710 URL : https://www.squirrelmail.org/ Summary : webmail client written in php Description : SquirrelMail is a basic webmail package written in PHP4. It includes built-in pure PHP support for the IMAP and SMTP protocols, and all pages render in pure HTML 4.0 (with no JavaScript) for maximum compatibility across browsers. It has very few requirements and is very easy to configure and install. --------------------------------------------------------------------------------Update Information: updated to 1.4 branch snapshot containing several security fixes --------------------------------------------------------------------------------ChangeLog: * Wed Jul 10 2019 Michal Hlavinka - 1.4.23-1.20190710 - squirrelmail updated to newer snapshot --------------------------------------------------------------------------------References: [ 1 ] Bug #1616100 - CVE-2018-14955 squirrelmail: persistent XSS in message display via SVG animations [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1616100 [ 2 ] Bug #1616097 - CVE-2018-14954 squirrelmail: persistent XSS in message display the formaction attribute [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1616097 [ 3 ] Bug #1616094 - CVE-2018-14953 squirrelmail: persistent XSS in message display via a "
A XSS vulnerability was discovered in SquirrelMail. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. Malicious script content from HTML e-mails can be executed within the application context via . Package : squirrelmail Version : 2:1.4.23~svn20120406-2+deb8u4 CVE ID : CVE-2019-12970 A XSS vulnerability was discovered in SquirrelMail. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. Malicious script content from HTML e-mails can be executed within the application context via crafted use of (for example) a NOEMBED, NOFRAMES, NOSCRIPT, or TEXTAREA element. For Debian 8 "Jessie", this problem has been fixed in version 2:1.4.23~svn20120406-2+deb8u4. We recommend that you upgrade your squirrelmail packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A significant cross-site scripting vulnerability in SquirrelMail impacts Debian 8. It is advisable to update for safeguarding against HTML script-related threats.. SquirrelMail Update, XSS Risk, Debian Security, Software Vulnerability. . Severity: Critical. LinuxSecurity.com Team
Updated squirrelmail packages fix XSS-security vulnerability: It was discovered that some special tags have not been filtered accordingly which can be used for an XSS-attack. . MGASA-2018-0357 - Updated squirrelmail packages fix XSS-security vulnerability Publication date: 31 Aug 2018 URL: https://advisories.mageia.org/MGASA-2018-0357.html Type: security Affected Mageia releases: 6 Updated squirrelmail packages fix XSS-security vulnerability: It was discovered that some special tags have not been filtered accordingly which can be used for an XSS-attack. References: - https://bugs.mageia.org/show_bug.cgi?id=23366 - - https://www.openwall.com/lists/oss-security/2018/07/26/2 SRPMS: - 6/core/squirrelmail-1.4.22-15.2.mga6 . The recent squirrelmail updates address an XSS vulnerability in Mageia 6 that impacts specific HTML tags. Check the advisory for complete details.. SquirrelMail Security Update, Mageia XSS Issue, Software Security Fix. . Severity: Important. LinuxSecurity.com Team
It was discovered that there were a number of Cross Site Scripting (XSS) vulnerabilities in the squirrelmail webmail client. For Debian 8 "Jessie", these issues has been fixed in squirrelmail . Package : squirrelmail Version : 2:1.4.23~svn20120406-2+deb8u3 CVE IDs : CVE-2018-14950 CVE-2018-14951 CVE-2018-14952 CVE-2018-14953 CVE-2018-14954 CVE-2018-14955 Debian Bug : #905023 It was discovered that there were a number of Cross Site Scripting (XSS) vulnerabilities in the squirrelmail webmail client. For Debian 8 "Jessie", these issues has been fixed in squirrelmail version 2:1.4.23~svn20120406-2+deb8u3. We recommend that you upgrade your squirrelmail packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'`
A vulnerability in SquirrelMail might allow remote attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201709-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: SquirrelMail: Remote Code Execution Date: September 17, 2017 Bugs: #616700 ID: 201709-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability in SquirrelMail might allow remote attackers to execute arbitrary code. Background ========= SquirrelMail is a webmail package written in PHP. It supports IMAP and SMTP and can optionally be installed with SQL support. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 mail-client/squirrelmail < 1.4.23_pre20140426 Vulnerable! ------------------------------------------------------------------- NOTE: Certain packages are still vulnerable. Users should migrate to another package if one is available or wait for the existing packages to be marked stable by their architecture maintainers. Description ========== It was discovered that the sendmail.cf file is mishandled in a popen call. Impact ===== A remote attacker, by enticing a user to open an e-mail attachment, could execute arbitrary shell commands. Workaround ========= There is no known workaround at this time. Resolution ========= Gentoo has discontinued support for SquirrelMail and recommends that users unmerge the package: # emerge --unmerge "mail-client/squirrelmail" References ========= [1 ] CVE-2017-7692 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-7692 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201709-13 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
fix insufficient escaping of user-supplied data (CVE-2017-7692). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-f85c37ae3d 2017-06-02 17:35:06.903270 --------------------------------------------------------------------------------Name : squirrelmail Product : Fedora 25 Version : 1.4.22 Release : 19.fc25 URL : https://www.squirrelmail.org/ Summary : webmail client written in php Description : SquirrelMail is a basic webmail package written in PHP4. It includes built-in pure PHP support for the IMAP and SMTP protocols, and all pages render in pure HTML 4.0 (with no JavaScript) for maximum compatibility across browsers. It has very few requirements and is very easy to configure and install. --------------------------------------------------------------------------------Update Information: fix insufficient escaping of user-supplied data (CVE-2017-7692) --------------------------------------------------------------------------------References: [ 1 ] Bug #1445165 - CVE-2017-7692 squirrelmail: Insufficient escaping of user-supplied data https://bugzilla.redhat.com/show_bug.cgi?id=1445165 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade squirrelmail' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.