REDHAT-BUG-500358: Low severity Squirrelmail Squirrelmail vulnerability
From SquirrelMail vulnerability report:
An issue was fixed that allowed an attacker to possibly steal user data by hijacking the SquirrelMail login session.
Credits: Tomas Hoger
Patch: http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail?view=rev&revision=13676
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-500358?
The severity of REDHAT-BUG-500358 is considered critical due to the potential for user data theft through session hijacking.
How do I fix REDHAT-BUG-500358?
To fix REDHAT-BUG-500358, update your SquirrelMail installation to the latest version that includes the security patch.
What versions of SquirrelMail are affected by REDHAT-BUG-500358?
REDHAT-BUG-500358 affects various versions of SquirrelMail prior to the patch release, particularly version 1.4.18 and earlier.
Can REDHAT-BUG-500358 lead to data breaches?
Yes, if exploited, REDHAT-BUG-500358 can lead to data breaches by allowing attackers to hijack user sessions.
Who reported the vulnerability in REDHAT-BUG-500358?
The vulnerability in REDHAT-BUG-500358 was reported by Tomas Hoger.