| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.51072 |
| Category: | Red Hat Local Security Checks |
| Title: | RedHat Security Advisory RHSA-2004:654 |
| Summary: | Redhat Security Advisory RHSA-2004:654 |
| Description: | The remote host is missing updates announced in advisory RHSA-2004:654. SquirrelMail is a webmail package written in PHP. A cross-site scripting bug has been found in SquirrelMail. This issue could allow an attacker to send a mail with a carefully crafted header, which could result in causing the victim's machine to execute a malicious script. The Common Vulnerabilities and Exposures project has assigned the name CVE-2004-1036 to this issue. Additionally, the following issues have been addressed: - - updated splash screens - - HIGASHIYAMA Masato's patch to improve Japanese support - - real 1.4.3a tarball - - config_local.php and default_pref in /etc/squirrelmail/ to match upstream RPM. Please note that it is possible that upgrading to this package may remove your SquirrelMail configuration files due to a bug in the RPM package. Upgrading will prevent this from happening in the future. Users of SquirrelMail are advised to upgrade to this updated package which contains a patched version of SquirrelMail version 1.43a and is not vulnerable to these issues. Solution: Please note that this update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date http://rhn.redhat.com/errata/RHSA-2004-654.html Risk factor : High |
| Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2004-1036 Bugtraq: 20041110 [SquirrelMail Security Advisory] Cross Site Scripting in encoded text (Google Search) http://marc.theaimsgroup.com/?l=bugtraq&m=110012133608004&w=2 http://lists.apple.com/archives/security-announce/2005/Jan/msg00001.html http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html Conectiva Linux advisory: CLA-2004:905 http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000905 http://www.gentoo.org/security/en/glsa/glsa-200411-25.xml http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9592 XForce ISS Database: squirrelmail-mime-xss(18031) http://xforce.iss.net/xforce/xfdb/18031 |
| Copyright | Copyright (c) 2005 E-Soft Inc. http://www.securityspace.com |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|