Gentoo Archives: gentoo-announce

From: Sune Kloppenborg Jeppesen <jaervosz@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200506-19 ] SquirrelMail: Several XSS vulnerabilities
Date: Tue, 21 Jun 2005 20:56:33
Message-Id: 200506212222.43071.jaervosz@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200506-19
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Low
8 Title: SquirrelMail: Several XSS vulnerabilities
9 Date: June 21, 2005
10 Bugs: #95937
11 ID: 200506-19
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Squirrelmail is vulnerable to several cross-site scripting
19 vulnerabilities which could lead to a compromise of webmail accounts.
20
21 Background
22 ==========
23
24 SquirrelMail is a webmail package written in PHP. It supports IMAP and
25 SMTP protocols.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 mail-client/squirrelmail < 1.4.4 >= 1.4.4
34 < 1.4.0
35
36 Description
37 ===========
38
39 SquirrelMail is vulnerable to several cross-site scripting issues, most
40 reported by Martijn Brinkers.
41
42 Impact
43 ======
44
45 By enticing a user to read a specially-crafted e-mail or using a
46 manipulated URL, an attacker can execute arbitrary scripts running in
47 the context of the victim's browser. This could lead to a compromise of
48 the user's webmail account, cookie theft, etc.
49
50 Workaround
51 ==========
52
53 There is no known workaround at this time.
54
55 Resolution
56 ==========
57
58 All SquirrelMail users should upgrade to the latest version:
59
60 # emerge --sync
61 # emerge --ask --oneshot --verbose ">=mail-client/squirrelmail-1.4.4"
62
63 Note: Users with the vhosts USE flag set should manually use
64 webapp-config to finalize the update.
65
66 References
67 ==========
68
69 [ 1 ] SquirrelMail Advisory
70 http://www.squirrelmail.org/security/issue/2005-06-15
71 [ 2 ] CAN-2005-1769
72 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1769
73
74 Availability
75 ============
76
77 This GLSA and any updates to it are available for viewing at
78 the Gentoo Security Website:
79
80 http://security.gentoo.org/glsa/glsa-200506-19.xml
81
82 Concerns?
83 =========
84
85 Security is a primary focus of Gentoo Linux and ensuring the
86 confidentiality and security of our users machines is of utmost
87 importance to us. Any security concerns should be addressed to
88 security@g.o or alternatively, you may file a bug at
89 http://bugs.gentoo.org.
90
91 License
92 =======
93
94 Copyright 2005 Gentoo Foundation, Inc; referenced text
95 belongs to its owner(s).
96
97 The contents of this document are licensed under the
98 Creative Commons - Attribution / Share Alike license.
99
100 http://creativecommons.org/licenses/by-sa/2.0