Oval Definition:oval:com.redhat.rhsa:def:20091066
Revision Date:2009-05-26Version:643
Title:RHSA-2009:1066: squirrelmail security update (Important)
Description:SquirrelMail is a standards-based webmail package written in PHP.

  • A server-side code injection flaw was found in the SquirrelMail "map_yp_alias" function. If SquirrelMail was configured to retrieve a user's IMAP server address from a Network Information Service (NIS) server via the "map_yp_alias" function, an unauthenticated, remote attacker using a specially-crafted username could use this flaw to execute arbitrary code with the privileges of the web server. (CVE-2009-1579)

  • Multiple cross-site scripting (XSS) flaws were found in SquirrelMail. An attacker could construct a carefully crafted URL, which once visited by an unsuspecting user, could cause the user's web browser to execute malicious script in the context of the visited SquirrelMail web page. (CVE-2009-1578)

  • It was discovered that SquirrelMail did not properly sanitize Cascading Style Sheets (CSS) directives used in HTML mail. A remote attacker could send a specially-crafted email that could place mail content above SquirrelMail's controls, possibly allowing phishing and cross-site scripting attacks. (CVE-2009-1581)

    Users of squirrelmail should upgrade to this updated package, which contains backported patches to correct these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2009-1578
    CVE-2009-1579
    CVE-2009-1581
    RHSA-2009:1066
    RHSA-2009:1066-01
    RHSA-2009:1066-01
    Platform(s):Red Hat Enterprise Linux 3
    Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND squirrelmail is earlier than 0:1.4.8-13.el3
  • AND squirrelmail is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND squirrelmail is earlier than 0:1.4.8-5.el4_8.5
  • AND squirrelmail is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND squirrelmail is earlier than 0:1.4.8-5.el5_3.7
  • AND squirrelmail is signed with Red Hat redhatrelease key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND squirrelmail is earlier than 0:1.4.8-5.el4_8.5
  • AND squirrelmail is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND squirrelmail is earlier than 0:1.4.8-5.el5_3.7
  • AND squirrelmail is signed with Red Hat redhatrelease2 key
  • BACK