First published: Thu May 21 2009(Updated: )
It was discovered that original upstream patch for server-side command execution flaw affecting setups with map_yp_alias username map enabled did not address the issue completely, due to incorrect use of quoting (backticks vs. single quotes). Code execution was still possible in upstream version 1.4.18. Issue was fixed upstream in 1.4.19. Updated upstream security advisory: <a href="http://www.squirrelmail.org/security/issue/2009-05-10">http://www.squirrelmail.org/security/issue/2009-05-10</a> Full upstream patch: <a href="http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/functions/imap_general.php?r1=13549&r2=13733">http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/functions/imap_general.php?r1=13549&r2=13733</a>
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
SquirrelMail imap general.php | =1.2.2 | |
SquirrelMail | =1.2.5 | |
SquirrelMail | =1.2.6 | |
SquirrelMail | =1.2.6-rc1 | |
SquirrelMail | =1.2.7 | |
SquirrelMail | =1.2.8 | |
SquirrelMail | =1.2.9 | |
SquirrelMail | =1.2.10 | |
SquirrelMail | =1.2.11 | |
SquirrelMail | =1.4.0 | |
SquirrelMail | =1.4.0-r1 | |
SquirrelMail | =1.4.1 | |
SquirrelMail | =1.4.2 | |
SquirrelMail | =1.4.2-r1 | |
SquirrelMail | =1.4.2-r2 | |
SquirrelMail | =1.4.2-r3 | |
SquirrelMail | =1.4.2-r4 | |
SquirrelMail | =1.4.2-r5 | |
SquirrelMail | =1.4.3_rc1 | |
SquirrelMail | =1.4.3_rc1-r1 | |
SquirrelMail | ||
SquirrelMail | =1.4.2 | |
SquirrelMail | =1.4.3_rc1 | |
SquirrelMail | =1.4.2-r3 | |
SquirrelMail | =1.4.2-r5 | |
SquirrelMail | ||
SquirrelMail | =1.4.2-r1 | |
SquirrelMail | =1.4.2-r2 | |
SquirrelMail | =1.4.2-r4 | |
SquirrelMail | =1.4.3_rc1-r1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2009-1381 is rated as high due to its potential for server-side command execution.
To fix CVE-2009-1381, ensure that you apply the latest patches provided by the SquirrelMail project for the affected versions.
CVE-2009-1381 affects SquirrelMail versions 1.2.2 to 1.4.1.
Yes, SquirrelMail versions 1.4.2 and later are not affected by CVE-2009-1381.
Systems with SquirrelMail configurations using the map_yp_alias username map enabled are at risk due to CVE-2009-1381.