First published: Tue Jul 10 2007(Updated: )
Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin before 2.1 for Squirrelmail might allow "local authenticated users" to inject certain commands via unspecified vectors. NOTE: this might overlap CVE-2005-1924, CVE-2006-4169, or CVE-2007-3634.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SquirrelMail | =1.4.10a | |
SquirrelMail GPG Plugin | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3635 is rated as a moderate severity vulnerability due to its potential for local authenticated users to inject commands.
To mitigate CVE-2007-3635, upgrade to a newer version of SquirrelMail and the GPG Plugin that address these vulnerabilities.
CVE-2007-3635 affects users of SquirrelMail version 1.4.10a and the GPG Plugin version 2.0.
CVE-2007-3635 describes multiple unspecified vulnerabilities that allow local authenticated users to potentially execute unauthorized commands.
Yes, CVE-2007-3635 may overlap with other vulnerabilities such as CVE-2005-1924, CVE-2006-4169, and CVE-2007-3634.