RHSA-2009:1490: Moderate: squirrelmail security update
SquirrelMail is a standards-based webmail package written in PHP.Form submissions in SquirrelMail did not implement protection againstCross-Site Request Forgery (CSRF) attacks. If a remote attacker tricked auser into visiting a malicious web page, the attacker could hijack thatuser's authentication, inject malicious content into that user'spreferences, or possibly send mail without that user's permission.(CVE-2009-2964)Users of SquirrelMail should upgrade to this updated package, whichcontains a backported patch to correct these issues.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2009:1490?
The severity of RHSA-2009:1490 is classified as moderate.
How do I fix RHSA-2009:1490?
To fix RHSA-2009:1490, upgrade SquirrelMail to version 1.4.8-5.el5_4.10 or higher.
What type of attack is associated with RHSA-2009:1490?
RHSA-2009:1490 is associated with Cross-Site Request Forgery (CSRF) attacks.
Which software is affected by RHSA-2009:1490?
RHSA-2009:1490 affects SquirrelMail versions prior to 1.4.8-5.el5_4.10.
What impact does RHSA-2009:1490 have on users?
If exploited, RHSA-2009:1490 could allow attackers to hijack user sessions.