Oval Definition:oval:com.redhat.rhsa:def:20060547
Revision Date:2006-07-03Version:638
Title:RHSA-2006:0547: squirrelmail security update (Moderate)
Description:SquirrelMail is a standards-based webmail package written in PHP4.

A local file disclosure flaw was found in the way SquirrelMail loads plugins. In SquirrelMail 1.4.6 or earlier, if register_globals is on and magic_quotes_gpc is off, it became possible for an unauthenticated remote user to view the contents of arbitrary local files the web server has read-access to. This configuration is neither default nor safe, and configuring PHP with the register_globals set on is dangerous and not recommended. (CVE-2006-2842)

Users of SquirrelMail should upgrade to this erratum package, which contains a backported patch to correct this issue.
Family:unixClass:patch
Status:Reference(s):CVE-2006-2842
RHSA-2006:0547
RHSA-2006:0547-01
RHSA-2006:0547-01
Platform(s):Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND squirrelmail is earlier than 0:1.4.6-7.el3
  • AND squirrelmail is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND squirrelmail is earlier than 0:1.4.6-7.el4
  • AND squirrelmail is signed with Red Hat master key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND squirrelmail is earlier than 0:1.4.6-7.el4
  • AND squirrelmail is signed with Red Hat redhatrelease2 key
  • BACK