Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: squirrelmail
Date: Sun, 15 Dec 2002 15:00:46
Message-Id: 20021215143846.0C9A233762@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200212-4
6 - - --------------------------------------------------------------------
7
8 PACKAGE : squirrelmail
9 SUMMARY : cross site scripting
10 DATE    : 2002-12-15 14:12 UTC
11 EXPLOIT : remote
12
13 - - --------------------------------------------------------------------
14
15 euronymous <just-a-user@××××××.ru> found that read_body.php didn't
16 filter out user input for 'filter_dir' and 'mailbox', making a xss
17 attack possible.
18
19 Read the full advisory at
20 http://f0kp.iplus.ru/bz/008.txt
21
22 SOLUTION
23
24 It is recommended that all Gentoo Linux users who are running
25 net-mail/squirrelmail-1.2.9 and earlier update their systems as follows:
26
27 emerge rsync
28 emerge squirrelmail
29 emerge clean
30
31 - - --------------------------------------------------------------------
32 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
33 - - --------------------------------------------------------------------
34 -----BEGIN PGP SIGNATURE-----
35 Version: GnuPG v1.2.1 (GNU/Linux)
36
37 iD8DBQE9/JPrfT7nyhUpoZMRAuUKAJ98w49ZxG/AzqPtINkcLHt83S568wCfeq+N
38 X8vYK73anWOOTITkoBwMRsY=
39 =5d7Y
40 -----END PGP SIGNATURE-----