[Midnightbsd-cvs] mports: mail/squirrelmail: functions/mime.php in SquirrelMail before

laffer1 at midnightbsd.org laffer1 at midnightbsd.org
Sat May 16 11:31:39 EDT 2009


Log Message:
-----------
functions/mime.php in SquirrelMail before 1.4.18 does not protect the application's content from Cascading Style Sheets (CSS) positioning in HTML e-mail messages, which allows remote attackers to spoof the user interface, and conduct cross-site scripting (XSS) and phishing attacks, via a crafted message. 

Session fixation vulnerability in SquirrelMail before 1.4.18 allows remote attackers to hijack web sessions via a crafted cookie

The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program.

Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.4.18 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) certain encrypted strings in e-mail headers, related to contrib/decrypt_headers.php; (2) PHP_SELF; and (3) the query string (aka QUERY_STRING).

Modified Files:
--------------
    mports/mail/squirrelmail:
        Makefile (r1.10 -> r1.11)
        (http://cvsweb.midnightbsd.org/mports/mail/squirrelmail/Makefile?r1=1.10&r2=1.11)
        distinfo (r1.8 -> r1.9)
        (http://cvsweb.midnightbsd.org/mports/mail/squirrelmail/distinfo?r1=1.8&r2=1.9)


More information about the Midnightbsd-cvs mailing list