漏洞信息详情
SquirrelMail文件夹名称跨站脚本漏洞
- CNNVD编号:CNNVD-200408-156
- 危害等级: 中危
- CVE编号:
CVE-2004-0519
- 漏洞类型:
跨站脚本
- 发布时间:
2004-08-18
- 威胁类型:
远程
- 更新时间:
2007-01-02
- 厂 商:
squirrelmail - 漏洞来源:
Disclosure of this… -
漏洞简介
SquirrelMail 1.4.2存在多个跨站脚本(XSS)漏洞。远程攻击者可以像其他用户一样通过多个包含compose.php邮箱参数的攻击向量来执行任意脚本并窃取身份验证信息。
漏洞公告
SquirrelMail 1.4.3 has been released to address this issue.
Gentoo has released an advisory (GLSA 200405-16) to address this issue. Please see the referenced advisory for more information. Gentoo users can carry out the following commands to upgrade their computers:
emerge sync
emerge -pv “>=net-mail/squirrelmail-1.4.3_rc1”
emerge “>=net-mail/squirrelmail-1.4.3_rc1”
Gentoo has released an advisory (GLSA 200405-16:02) to address errors in the previous Gentoo advisory. Please see the referenced advisory for more information.
RedHat has released an advisory (FEDORA-2004-160) to address this and other issues in Fedora Core 2. Please see the referenced advisory for more information.
RedHat has released an advisory (RHSA-2004:240-06) to address this and other issues in Red Hat Enterprise Linux. Please see the advisory in web references for more information.
SGI has released a security advisory (20040604-01-U) to address this and other issues in SGI ProPack 3. Please see the referenced advisory for more information.
Debian has released security advisory DSA 535-1 with fixes to address this issue.
Conectiva has released a security advisory (CLA-2004:858) to address multiple issues in SquirrelMail. Please see the referenced advisory for more information.
The Fedora Legacy project has released advisory FLSA:1733 along with fixes to address multiple issues in SquirrelMail for RedHat Linux 9. Please see the referenced advisory for further information.
SUSE has released a security summary report (SUSE-SR:2005:019) addressing this and other issues. Please see the referenced advisory for further information.
SquirrelMail SquirrelMail 1.0.4
-
SquirrelMail SquirrelMail 1.4.3-RC1
http://sourceforge.net/project/showfiles.php?group_id=311&package_id=3
34&release_id=237332
SquirrelMail SquirrelMail 1.0.5
-
SquirrelMail SquirrelMail 1.4.3-RC1
http://sourceforge.net/project/showfiles.php?group_id=311&package_id=3
34&release_id=237332
SquirrelMail SquirrelMail 1.2 .0
-
SquirrelMail SquirrelMail 1.4.3-RC1
http://sourceforge.net/project/showfiles.php?group_id=311&package_id=3
34&release_id=237332
SquirrelMail SquirrelMail 1.2.1
-
SquirrelMail SquirrelMail 1.4.3-RC1
http://sourceforge.net/project/showfiles.php?group_id=311&package_id=3
34&release_id=237332
SquirrelMail SquirrelMail 1.2.10
-
SquirrelMail SquirrelMail 1.4.3-RC1
http://sourceforge.net/project/showfiles.php?group_id=311&package_id=3
34&release_id=237332
SquirrelMail SquirrelMail 1.2.11
-
SquirrelMail SquirrelMail 1.4.3-RC1
http://sourceforge.net/project/showfiles.php?group_id=311&package_id=3
34&release_id=237332
SquirrelMail SquirrelMail 1.2.2
-
SquirrelMail SquirrelMail 1.4.3-RC1
http://sourceforge.net/project/showfiles.php?group_id=311&package_id=3
34&release_id=237332
SquirrelMail SquirrelMail 1.2.3
-
SquirrelMail SquirrelMail 1.4.3-RC1
http://sourceforge.net/project/showfiles.php?group_id=311&package_id=3
34&release_id=237332
SquirrelMail SquirrelMail 1.2.4
-
SquirrelMail SquirrelMail 1.4.3-RC1
http://sourceforge.net/project/showfiles.php?group_id=311&package_id=3
34&release_id=237332
SquirrelMail SquirrelMail 1.2.5
-
SquirrelMail SquirrelMail 1.4.3-RC1
http://sourceforge.net/project/showfiles.php?group_id=311&package_id=3
34&release_id=237332
SquirrelMail SquirrelMail 1.2.6
-
Conectiva squirrelmail-1.4.3a-13677U90_1cl.noarch.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/squirrelmail-1.4.3a-13677U9
0_1cl.noarch.rpm -
Conectiva squirrelmail-doc-1.4.3a-13677U90_1cl.noarch.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/squirrelmail-doc-1.4.3a-136
77U90_1cl.noarch.rpm -
Debian squirrelmail_1.2.6-1.4_all.debDebian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squirrelmail/squirrelma
il_1.2.6-1.4_all.deb -
SquirrelMail SquirrelMail 1.4.3-RC1
http://sourceforge.net/project/showfiles.php?group_id=311&package_id=3
34&release_id=237332
SquirrelMail SquirrelMail 1.2.7
-
SquirrelMail SquirrelMail 1.4.3-RC1
http://sourceforge.net/project/showfiles.php?group_id=311&package_id=3
34&release_id=237332
SquirrelMail SquirrelMail 1.2.8
-
SquirrelMail SquirrelMail 1.4.3-RC1
http://sourceforge.net/project/showfiles.php?group_id=311&package_id=3
34&release_id=237332
SquirrelMail SquirrelMail 1.2.9
-
SquirrelMail SquirrelMail 1.4.3-RC1
http://sourceforge.net/project/showfiles.php?group_id=311&package_id=3
34&release_id=237332
SquirrelMail SquirrelMail 1.4
-
SquirrelMail SquirrelMail 1.4.3-RC1
http://sourceforge.net/project/showfiles.php?group_id=311&package_id=3
34&release_id=237332
SquirrelMail SquirrelMail 1.4.1
-
SquirrelMail SquirrelMail 1.4.3-RC1
http://sourceforge.net/project/showfiles.php?group_id=311&package_id=3
34&release_id=237332
SquirrelMail SquirrelMail 1.4.2
-
SquirrelMail SquirrelMail 1.4.3-RC1
http://sourceforge.net/project/showfiles.php?group_id=311&package_id=3
34&release_id=237332
SGI ProPack 3.0
-
SGI patch10083.tar.gz
ft
参考网址
来源: FEDORA
名称: FEDORA-2004-1733
链接:https://bugzilla.fedora.us/show_bug.cgi?id=1733
来源: BID
名称: 10246
链接:http://www.securityfocus.com/bid/10246
来源: FEDORA
名称: FEDORA-2004-160
链接:http://www.securityfocus.com/advisories/6827
来源: DEBIAN
名称: DSA-535
链接:http://www.debian.org/security/2004/dsa-535
来源: SECUNIA
名称: 12289
链接:http://secunia.com/advisories/12289
来源: SECUNIA
名称: 11870
链接:http://secunia.com/advisories/11870
来源: SECUNIA
名称: 11686
链接:http://secunia.com/advisories/11686
来源: SECUNIA
名称: 11531
链接:http://secunia.com/advisories/11531
来源: REDHAT
名称: RHSA-2004:240
链接:http://rhn.redhat.com/errata/RHSA-2004-240.html
来源: SGI
名称: 20040604-01-U
链接:ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc
来源: XF
名称: squirrel-composephp-xss(16025)
链接:http://xforce.iss.net/xforce/xfdb/16025
来源: BUGTRAQ
名称: 20040430 Re: SquirrelMail Cross Scripting Attacks….
链接:http://www.securityfocus.com/archive/1/361857
来源: SUSE
名称: SUSE-SR:2005:019
链接:http://www.novell.com/linux/security/advisories/2005_19_sr.html
来源: GENTOO
名称: GLSA-200405-16
链接:http://security.gentoo.org/glsa/glsa-200405-16.xml
来源: OVAL
名称: oval:org.mitre.oval:def:10274
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10274
来源: BUGTRAQ
名称: 20040429 SquirrelMail Cross Scripting Attacks….
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=108334862800260
来源: CONECTIVA
名称: CLA-2004:858
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000858
来源: US Government Resource: oval:org.mitre.oval:def:1006
名称: oval:org.mitre.oval:def:1006
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1006