SquirrelMail文件夹名称跨站脚本漏洞

漏洞信息详情

SquirrelMail文件夹名称跨站脚本漏洞

漏洞简介

SquirrelMail 1.4.2存在多个跨站脚本(XSS)漏洞。远程攻击者可以像其他用户一样通过多个包含compose.php邮箱参数的攻击向量来执行任意脚本并窃取身份验证信息。

漏洞公告

SquirrelMail 1.4.3 has been released to address this issue.
Gentoo has released an advisory (GLSA 200405-16) to address this issue. Please see the referenced advisory for more information. Gentoo users can carry out the following commands to upgrade their computers:
emerge sync
emerge -pv “>=net-mail/squirrelmail-1.4.3_rc1”
emerge “>=net-mail/squirrelmail-1.4.3_rc1”
Gentoo has released an advisory (GLSA 200405-16:02) to address errors in the previous Gentoo advisory. Please see the referenced advisory for more information.
RedHat has released an advisory (FEDORA-2004-160) to address this and other issues in Fedora Core 2. Please see the referenced advisory for more information.
RedHat has released an advisory (RHSA-2004:240-06) to address this and other issues in Red Hat Enterprise Linux. Please see the advisory in web references for more information.
SGI has released a security advisory (20040604-01-U) to address this and other issues in SGI ProPack 3. Please see the referenced advisory for more information.
Debian has released security advisory DSA 535-1 with fixes to address this issue.
Conectiva has released a security advisory (CLA-2004:858) to address multiple issues in SquirrelMail. Please see the referenced advisory for more information.
The Fedora Legacy project has released advisory FLSA:1733 along with fixes to address multiple issues in SquirrelMail for RedHat Linux 9. Please see the referenced advisory for further information.
SUSE has released a security summary report (SUSE-SR:2005:019) addressing this and other issues. Please see the referenced advisory for further information.
SquirrelMail SquirrelMail 1.0.4

SquirrelMail SquirrelMail 1.0.5

SquirrelMail SquirrelMail 1.2 .0

SquirrelMail SquirrelMail 1.2.1

SquirrelMail SquirrelMail 1.2.10

SquirrelMail SquirrelMail 1.2.11

SquirrelMail SquirrelMail 1.2.2

SquirrelMail SquirrelMail 1.2.3

SquirrelMail SquirrelMail 1.2.4

SquirrelMail SquirrelMail 1.2.5

SquirrelMail SquirrelMail 1.2.6

SquirrelMail SquirrelMail 1.2.7

SquirrelMail SquirrelMail 1.2.8

SquirrelMail SquirrelMail 1.2.9

SquirrelMail SquirrelMail 1.4

SquirrelMail SquirrelMail 1.4.1

SquirrelMail SquirrelMail 1.4.2

SGI ProPack 3.0

  • SGI patch10083.tar.gz
    ft

参考网址

来源: FEDORA
名称: FEDORA-2004-1733
链接:https://bugzilla.fedora.us/show_bug.cgi?id=1733

来源: BID
名称: 10246
链接:http://www.securityfocus.com/bid/10246

来源: FEDORA
名称: FEDORA-2004-160
链接:http://www.securityfocus.com/advisories/6827

来源: DEBIAN
名称: DSA-535
链接:http://www.debian.org/security/2004/dsa-535

来源: SECUNIA
名称: 12289
链接:http://secunia.com/advisories/12289

来源: SECUNIA
名称: 11870
链接:http://secunia.com/advisories/11870

来源: SECUNIA
名称: 11686
链接:http://secunia.com/advisories/11686

来源: SECUNIA
名称: 11531
链接:http://secunia.com/advisories/11531

来源: REDHAT
名称: RHSA-2004:240
链接:http://rhn.redhat.com/errata/RHSA-2004-240.html

来源: SGI
名称: 20040604-01-U
链接:ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc

来源: XF
名称: squirrel-composephp-xss(16025)
链接:http://xforce.iss.net/xforce/xfdb/16025

来源: BUGTRAQ
名称: 20040430 Re: SquirrelMail Cross Scripting Attacks….
链接:http://www.securityfocus.com/archive/1/361857

来源: SUSE
名称: SUSE-SR:2005:019
链接:http://www.novell.com/linux/security/advisories/2005_19_sr.html

来源: GENTOO
名称: GLSA-200405-16
链接:http://security.gentoo.org/glsa/glsa-200405-16.xml

来源: OVAL
名称: oval:org.mitre.oval:def:10274
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10274

来源: BUGTRAQ
名称: 20040429 SquirrelMail Cross Scripting Attacks….
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=108334862800260

来源: CONECTIVA
名称: CLA-2004:858
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000858

来源: US Government Resource: oval:org.mitre.oval:def:1006
名称: oval:org.mitre.oval:def:1006
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1006

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享