CVE-2005-0239: High severity Squirrelmail S Mime Plugin vulnerability
Published Feb 7, 2005
·Updated
viewcert.php in the S/MIME plugin 0.4 and 0.5 for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacters in the cert parameter.
Affected Software
2 affected components
Squirrelmail S Mime Plugin=0.5
Squirrelmail S Mime Plugin=0.4
Remediation
Patch Available
Event History
Feb 7, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0239?
CVE-2005-0239 is considered to have a high severity due to its potential for remote command execution.
2
How do I fix CVE-2005-0239?
To fix CVE-2005-0239, upgrade the S/MIME plugin to version 0.6 or later, where the vulnerability has been addressed.
3
Who is affected by CVE-2005-0239?
CVE-2005-0239 affects users of SquirrelMail using S/MIME Plugin versions 0.4 and 0.5.
4
What kind of attacks can exploit CVE-2005-0239?
CVE-2005-0239 can be exploited by remote attackers to execute arbitrary commands through malformed input in the cert parameter.
5
Is CVE-2005-0239 a known vulnerability?
Yes, CVE-2005-0239 is a known vulnerability that has been documented for over a decade.